RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Karmadav1.17.2Orchestration & ManagementApr 30, 2026

v1.17.2 contains correctness fixes and a security-related Alpine base-image dependency update. The alpine update requires upgrading to receive the new base image.

Action needed (1)

  • securityThe alpine base image, updated to alpine:3.23.4

    The base image alpine has been updated from alpine:3.23.3 to alpine:3.23.4 to address security concerns. The update ships in v1.17.2.

Source
Karmadav1.15.8Orchestration & ManagementApr 30, 2026

A maintenance release includes corrected operator and scheduler behavior, along with an updated Alpine base image. The Alpine update addresses security concerns.

Action needed (1)

  • securityThe alpine base image, updated

    The base image alpine was updated from alpine:3.23.3 to alpine:3.23.4 to address security concerns. The update ships in the release.

Source
KServev0.18.0AI & MLApr 29, 2026

A release with operator-facing fixes, new capabilities, API and configuration changes, and dependency updates. It also includes fixes for CVE-2026-32597 in PyJWT and CVE-2026-30922 in pyasn1.

Action needed (3)

  • securityhighCVE-2026-32597 PyJWT validation fix

    PyJWT crit header validation was fixed for CVE-2026-32597.

  • securityhighCVE-2026-30922 pyasn1 fix

    The pyasn1 dependency was updated to address CVE-2026-30922 and its denial-of-service vulnerability.

  • breakingRequired MaxReplicas field

    MaxReplicas is now required and must use the int32 type.

Check if affected (2)

  • breakingRemoval of the scheduler cert-hash restart annotation

    Applies if you configure cert-hash.

  • breakingPYTHONPATH blocked by ISVC and ServingRuntime webhooks

    Applies if you configure PYTHONPATH.

Source
Kyvernov1.18.0SecurityApr 29, 2026

A substantial feature and maintenance release with new operator capabilities plus configuration, Helm, and CLI improvements. It also includes defect, output, dependency, and security fixes, including remediation for several CVE-related issues.

Action needed (4)

  • securityhighIntermediate certificate limit for CVE-2026-32280

    Intermediate certificates are limited to mitigate CVE-2026-32280 in this release.

  • securityhighGo toolchain upgraded to 1.26.2 for CVE-2026-32283

    The Go toolchain is upgraded to 1.26.2 to fix CVE-2026-32283.

  • securitymediumgo-tuf/v2 upgraded to v2.4.1 for CVE-2026-24686

    go-tuf/v2 is upgraded to v2.4.1 to fix CVE-2026-24686.

  • securityStandard library CVE fixes

    Standard library CVEs are fixed in this release.

Check if affected (2)

  • breakingRestricted ConfigMap access for namespaced policies

    Applies if you use namespaced policies.

  • breakingFinalizers and uninstall workarounds removed

    Applies if uninstall runs.

Source
Strimzi1.0.0Networking & MessagingApr 28, 2026

A release that removes older CRD API versions, changes defaults and configuration locations, and adds Kafka and HTTP Bridge capabilities. Monitoring configurations and standalone Topic Operator setups may require updates.

Action needed (2)

  • breakingThe UseConnectBuildWithBuildah feature gate, enabled by default

    The UseConnectBuildWithBuildah feature gate moves to the beta stage and is enabled by default.

  • breakingThe /metrics endpoint, moved to the HTTP management interface

    The /metrics endpoint is no longer available on the regular HTTP interface, which uses port 8080 by default. It is now available on the HTTP management interface on port 8081.

Check if affected (4)

  • breakingOlder CRD API versions, removed

    Applies if you use the v1beta2, v1beta1, or v1alpha1 CRD APIs.

  • breakingThe Open Policy Agent (OPA) authorizer plugin, no longer bundled

    Applies if you use the Open Policy Agent (OPA) authorizer plugin.

  • breakingLegacy TLS environment variables, ignored

    Applies if you set any of STRIMZI_TLS_ENABLED, STRIMZI_TLS_AUTH_ENABLED, STRIMZI_PUBLIC_CA, STRIMZI_TRUSTSTORE_LOCATION, STRIMZI_TRUSTSTORE_PASSWORD, STRIMZI_KEYSTORE_LOCATION, or STRIMZI_KEYSTORE_PASSWORD.

  • + 1 more on the release page
Source
NATSv2.12.8Networking & MessagingApr 27, 2026

A maintenance release with a security fix, correctness fixes, a performance improvement, and dependency and toolchain manifest updates. Most changes take effect through the release itself without additional operator action.

Action needed (1)

  • securityBearer JWT disclosure fix in /connz

    The /connz monitoring endpoint no longer discloses bearer JWTs. The fix ships in the NATS monitoring endpoint.

Source
OpenFGAv1.15.0SecurityApr 27, 2026

This release updates the Go toolchain alongside changes to authorization behavior. The Go update addresses standard library vulnerabilities documented in the Go 1.26.2 release notes.

Action needed (1)

  • securityThe Go toolchain version, updated to 1.26.2

    The toolchain Go version is updated to 1.26.2 to address Go standard library vulnerabilities documented in the Go 1.26.2 release notes.

Source
Flatcar Container Linuxlts-4081.3.7Provisioning & RuntimeApr 27, 2026

This is primarily a security-focused Flatcar release with a large set of disclosed Linux fixes. It also includes a QEMU launcher performance correction and updates to Linux and ca-certificates dependencies.

Action needed (1)

  • securitycriticalLinux security fixes

    Linux is updated with fixes for the disclosed advisories, including CVE-2023-52435, the CVE-2025-* and CVE-2026-* advisories listed for this release. The fixes ship in Flatcar lts-4081.3.7.

Source
Flatcar Container Linuxstable-4593.2.0Provisioning & RuntimeApr 27, 2026

A security- and maintenance-focused release with updates to Linux and bundled components, along with dependency updates. It also corrects minimal-initrd regressions and changes service startup, SSH defaults, kernel-module availability, and other operator-visible behavior and layout.

Action needed (18)

Check if affected (1)

  • breakingAutomatic startup for overlaybd sysext services

    Applies if you use the overlaybd sysext.

Source
Cortexv1.21.0ObservabilityApr 27, 2026

A feature and maintenance release that adds Store Gateway, federation, overrides, caching, metric, and query capabilities while graduating several experimental features. It also changes defaults and configuration names, updates dependencies, and fixes correctness, memory, panic, and data-corruption defects.

Action needed (1)

  • breakingThe blocks storage bucket index default

    Blocks storage now enables the bucket index by default through -blocks-storage.bucket-store.bucket-index.enabled. Disabling it with -blocks-storage.bucket-store.bucket-index.enabled=false is not recommended for production.

Check if affected (1)

  • breakingThe Distributor type and unit label flag

    Applies if you configure either -distributor.enable-type-and-unit-labels or -distributor.otlp.enable-type-and-unit-labels for remote write v2 and OTLP requests.

Plan ahead (3)

  • breakingThe Ruler API flag rename

    Applies if you configure -experimental.ruler.enable-api.

  • breakingThe Alertmanager API flag rename

    Applies if you configure -experimental.alertmanager.enable-api.

  • breakingThe Users Scanner user index update configuration

    Applies if you configure either -*.users-scanner.user-index.cleanup-interval or clean_up_interval.

Source
wasmCloudv2.0.5Orchestration & ManagementApr 24, 2026

This release adds the Val map type, Linux glibc GPU builds, and updates to wasmtime and its rustls dependency. It also corrects pooling allocator probing and includes a security update for rustls-webpki.

Action needed (1)

  • securityrustls-webpki security update, RUSTSEC-2026-0049

    The release includes a security update for rustls-webpki, addressing RUSTSEC-2026-0049.

Source
Crossplanev1.20.7Orchestration & ManagementApr 24, 2026

This release updates the Go toolchain in Crossplane to 1.25.9. The change addresses undisclosed standard-library CVEs.

Action needed (1)

  • securityThe Go toolchain, updated to 1.25.9

    Crossplane v1.20.7 updates the Go toolchain to 1.25.9. The update addresses undisclosed standard-library CVEs.

Source
Envoyv1.38.0Networking & MessagingApr 23, 2026

A release with breaking configuration and flag changes, many new extension and protocol capabilities, and fixes for security, correctness, and observability. The recorded additions include module and filter extension APIs, MCP and A2A protocol support, OpenSSL builds, new formatters and metrics, and expanded streaming and TLS capabilities.

Action needed (1)

  • securityhighnghttp2 **CVE-2026-27135** patch

    The nghttp2 **CVE-2026-27135** patch is included.

Check if affected (6)

  • securityURL encoding for query_parameter_mutations values

    Applies if you configure query_parameter_mutations.

  • securityRBAC concatenation-based bypass prevention

    Applies if RBAC runs.

  • breakingExplicit max_early_data_bytes configuration

    Applies if you configure upstream_connect_mode with a value other than IMMEDIATE and do not configure max_early_data_bytes.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedThe enforce_rsa_key_usage option, deprecatedremoval date not announced

    Applies if you configure enforce_rsa_key_usage.

Source
Kyvernov1.16.4SecurityApr 23, 2026

A security-fix release with fixes for multiple CVEs and updates to affected dependencies. It also changes the default HTTP behavior and restricts configmap access for namespaced policies.

Action needed (12)

  • securitycriticalCVE-2025-68121 fix

    This release fixes CVE-2025-68121.

  • securitycriticalCVE-2026-33186 fix

    This release fixes CVE-2026-33186.

  • securityhighCVE-2026-24051 fix

    This release fixes CVE-2026-24051 in the 1.16 release line.

  • securityhighThe github.com/docker/cli dependency update

    The github.com/docker/cli dependency is updated to resolve CVE-2025-15558.

  • securityhighCVE-2025-66564 fix

    This release resolves CVE-2025-66564.

  • securitymediumThe sigstore/rekor dependency update to v1.5.1

    The sigstore/rekor dependency is updated to v1.5.1 to fix CVE-2026-23831.

  • securitymediumThe go-tuf/v2 dependency update to v2.3.1

    The go-tuf/v2 dependency is updated to v2.3.1 to address CVE-2026-23992.

  • securitymediumCVE-2026-22772 fix

    This release fixes CVE-2026-22772.

  • securitymediumThe go-tuf/v2 dependency update to v2.4.1

    The go-tuf/v2 dependency is updated to v2.4.1 to patch CVE-2026-24686.

  • securitylowCVE-2026-1229 fix

    This release fixes CVE-2026-1229 in the 1.16 release line.

  • securitylowCVE-2026-26958 fix

    This release fixes CVE-2026-26958.

  • securityStandard library CVE fixes

    This release fixes standard library CVEs.

Check if affected (3)

  • securitycriticalHTTP disabled by default in namespaced policies

    Applies if you configure namespaced policies.

  • securityCVE fixes for go < 1.25.8

    Applies if you depend on go < 1.25.8.

  • breakingRestricted configmap access for namespaced policies

    Applies if you configure namespaced policies.

Source
Kyvernov1.17.2SecurityApr 23, 2026

A maintenance release with multiple correctness fixes and security fixes, including changes for several CVEs and standard library CVEs. Operators should account for the changed HTTP default and narrower configmap access in addition to the security fixes.

Action needed (6)

  • securitycriticalCVE-2026-33186 correction

    The release fixes CVE-2026-33186.

  • securityhighCVE-2026-24051 correction

    The release fixes CVE-2026-24051 in the 1.17 release line.

  • securityhighCVE-2026-34986 correction

    The release fixes CVE-2026-34986.

  • securitylowCVE-2026-1229 correction

    The release fixes CVE-2026-1229.

  • securityCVES 2026-15558 correction

    The release includes the CVES 2026-15558 fix for 1.17.

  • securityGo version update

    The Go version was bumped to fix standard library CVEs.

Check if affected (2)

  • securitycriticalHTTP default for namespaced policies

    Applies if you configure namespaced policies.

  • breakingConfigmap access for namespaced policies

    Applies if you configure namespaced policies.

Source
Kubernetesv1.36.0Kubernetes CoreApr 22, 2026

A broad operator-significant release with API, configuration, CLI default, scheduling, runtime, feature-gate, metric, and dependency changes. Upgrade review and testing matter for users of removed or deprecated interfaces, changed defaults, custom scheduler integrations, CRDs, audit logging, and affected metrics.

Action needed (11)

  • breakingStrictIPCIDRValidation enabled by default

    The StrictIPCIDRValidation feature gate in kube-apiserver is enabled by default.

  • breakingThe default debug profile, changed to general

    The default debug profile changes from legacy to general.

  • breakingWatchCacheInitializationPostStartHook enabled by default

    The WatchCacheInitializationPostStartHook feature gate is enabled by default.

  • breakingKubeletPSI graduation to GA

    The KubeletPSI feature graduated to GA and is enabled by default.

  • breakingRelaxedServiceNameValidation at beta, enabled by default

    The RelaxedServiceNameValidation feature gate graduated to beta and is enabled by default.

  • breakingRestartAllContainersOnContainerExits at beta, enabled by default

    The RestartAllContainersOnContainerExits feature gate graduated to beta and is enabled by default.

  • breakingSuspended-job feature gates enabled by default

    The MutablePodResourcesForSuspendedJobs and MutableSchedulingDirectivesForSuspendedJobs feature gates are enabled by default.

  • breakingAtomicFIFO informer store updates

    Default informer behavior now updates store state with all objects in a list or relist before invoking individual-item handler methods. This behavior is associated with AtomicFIFO.

  • breakingUnlockWhileProcessing informer behavior

    Informers can now enqueue new watch events while already-queued events are being processed. This behavior is associated with UnlockWhileProcessing.

  • breakingClientsAllowCARotation functionality enabled by default

    This functionality is enabled by default and can be disabled through the ClientsAllowCARotation feature gate.

  • breakingClientsAllowTLSCacheGC functionality enabled by default

    This functionality is enabled by default and can be controlled through the ClientsAllowTLSCacheGC feature gate.

Check if affected (25)

  • breakingThe volume_operation_total_errors metric, renamed

    Applies if you use volume_operation_total_errors.

  • breakingThe git-repo volume plugin, disabled

    Applies if you use the git-repo volume plugin.

  • breakingAllowlistEntry.Name, renamed to AllowlistEntry.Command

    Applies if you configure AllowlistEntry.Name.

  • + 22 more on the release page

Plan ahead (6)

  • deprecatedService .spec.externalIPs deprecation

    Applies if you configure Service .spec.externalIPs.

  • deprecatedDirect access to metav1.FieldsV1.Raw, deprecated

    Applies if you use metav1.FieldsV1.Raw.

  • deprecatedMinNodeScore and MaxNodeScore, deprecated

    Applies if you use MinNodeScore or MaxNodeScore.

  • + 3 more on the release page
Source
metal3-iov0.12.4Provisioning & RuntimeApr 22, 2026

This release fixes an HFC controller error loop, removes unused RBAC permissions, and updates project dependencies. The changes cover controller correctness and routine maintenance, with no stated security advisory.

Action needed (1)

  • breakingUnused permissions in the controller ClusterRole removed

    Unused RBAC permissions are removed from the controller ClusterRole.

Source
metal3-iov0.11.7Provisioning & RuntimeApr 22, 2026

This release removes unused controller permissions and includes fixes and dependency updates. It may concern users tracking HFC controller behavior, CAPI, the Kubernetes group, or the Go build toolchain.

Action needed (1)

  • breakingUnused controller ClusterRole RBAC permissions removed

    Unused RBAC permissions are removed from the controller ClusterRole in this release.

Source
CoreDNSv1.14.3Kubernetes CoreApr 22, 2026

A maintenance release that adds operator-facing options and transport, plugin, and protocol support while correcting defects. It is built with Go 1.26.2, which contains fixes for disclosed CVEs; other changes concern operators using the affected features or behaviors.

Action needed (1)

Check if affected (1)

  • breakingOversized DoH GET query parameter rejection

    Applies if you use DoH.

Source
cert-managerv1.19.5SecurityApr 21, 2026

This release contains security-related updates to Go dependencies and the Go toolchain. It concerns deployments that rely on the affected dependencies or the bundled Go toolchain.

Action needed (2)

  • securityGo dependencies with reported vulnerabilities updated

    Go dependencies with reported vulnerabilities are updated in cert-manager v1.19.5.

  • securityThe go toolchain updated to 1.25.8

    The go toolchain is updated to 1.25.8 in cert-manager v1.19.5 to address reported vulnerabilities.

Source
KubeVirtv1.8.2Orchestration & ManagementApr 20, 2026

A correctness-focused release also changes backend volume naming and removes permissions from the kubevirt.io:edit RBAC role. The RBAC change requires operator attention.

Action needed (1)

  • breakingThe kubevirt.io:edit RBAC role, with vnc and screenshot permissions removed

    The vnc and screenshot permissions are removed from the kubevirt.io:edit RBAC role in this release.

Source
Contourv1.32.5Networking & MessagingApr 20, 2026

Contour v1.32.5 fixes a Lua code injection vulnerability and upgrades Envoy to v1.34.14. The release also includes an informational Kubernetes compatibility update.

Action needed (1)

  • securityhighCVE-2026-41246 Lua code injection vulnerability fixed

    This release fixes CVE-2026-41246 and GHSA-x4mj-7f9g-29h4, a Lua code injection vulnerability affecting cookieRewritePolicies[].pathRewrite.value.

Source
Crossplanev2.2.1Orchestration & ManagementApr 20, 2026

Crossplane v2.2.1 includes security-focused dependency updates and a move to Go 1.25.9. It also corrects operator-facing behavior around dependency upgrades with ImageConfig prefix rewrites and resource selectors, and bumps Crossplane Runtime to v2.2.1.

Action needed (10)

  • securityThe github.com/cloudflare/circl module, updated to v1.6.3

    Crossplane v2.2.1 updates the github.com/cloudflare/circl module to v1.6.3 as a security dependency change.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module, updated to v1.43.0

    Crossplane v2.2.1 updates the go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module to v1.43.0 as a security dependency change.

  • securityThe github.com/go-jose/go-jose/v4 module, updated to v4.1.4

    Crossplane v2.2.1 updates the github.com/go-jose/go-jose/v4 module to v4.1.4 as a security dependency change.

  • securityThe github.com/sigstore/cosign/v3 module, updated to v3.0.5

    Crossplane v2.2.1 updates the github.com/sigstore/cosign/v3 module to v3.0.5 as a security dependency change.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.17.1

    Crossplane v2.2.1 updates the github.com/go-git/go-git/v5 module to v5.17.1 as a security dependency change.

  • securityThe github.com/docker/cli module, updated to v29.2.0+incompatible

    Crossplane v2.2.1 updates the github.com/docker/cli module to v29.2.0+incompatible as a security dependency change.

  • securityGo 1.25.9

    Crossplane v2.2.1 updates Go to 1.25.9 as a security dependency change.

  • securityThe github.com/moby/spdystream module, updated to v0.5.1

    Crossplane v2.2.1 updates the github.com/moby/spdystream module to v0.5.1 as a security dependency change.

  • securityThe github.com/sigstore/timestamp-authority/v2 module, updated to v2.0.6

    Crossplane v2.2.1 updates the github.com/sigstore/timestamp-authority/v2 module to v2.0.6 as a security dependency change.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.18.0

    Crossplane v2.2.1 updates the github.com/go-git/go-git/v5 module to v5.18.0 as a security dependency change.

Source
Crossplanev2.1.5Orchestration & ManagementApr 20, 2026

Crossplane v2.1.5 combines correctness fixes with dependency and Go toolchain updates. The release includes updated versions of several modules used by Crossplane.

Action needed (10)

  • securityThe github.com/cloudflare/circl module, updated to v1.6.3

    Crossplane v2.1.5 updates the github.com/cloudflare/circl module to v1.6.3.

  • securityThe google.golang.org/grpc module, updated to v1.79.3

    Crossplane v2.1.5 updates the google.golang.org/grpc module to v1.79.3.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module, updated to v1.43.0

    Crossplane v2.1.5 updates the go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module to v1.43.0.

  • securityThe github.com/go-jose/go-jose/v4 module, updated to v4.1.4

    Crossplane v2.1.5 updates the github.com/go-jose/go-jose/v4 module to v4.1.4.

  • securityThe Go toolchain, updated to 1.25.9

    Crossplane v2.1.5 updates the Go toolchain to 1.25.9.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.17.1

    Crossplane v2.1.5 updates the github.com/go-git/go-git/v5 module to v5.17.1.

  • securityThe github.com/moby/spdystream module, updated to v0.5.1

    Crossplane v2.1.5 updates the github.com/moby/spdystream module to v0.5.1.

  • securityThe github.com/sigstore/timestamp-authority/v2 module, updated to v2.0.6

    Crossplane v2.1.5 updates the github.com/sigstore/timestamp-authority/v2 module to v2.0.6.

  • securityThe github.com/docker/cli module, updated to v29.2.0+incompatible

    Crossplane v2.1.5 updates the github.com/docker/cli module to v29.2.0+incompatible.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.18.0

    Crossplane v2.1.5 updates the github.com/go-git/go-git/v5 module to v5.18.0.

Source
Crossplanev2.0.8Orchestration & ManagementApr 20, 2026

Crossplane v2.0.8 corrects two operator-visible defects and updates Go plus several dependencies. The dependency changes are marked for security, but the disclosures identify only the affected components rather than specific advisory IDs.

Action needed (9)

  • securityThe github.com/cloudflare/circl module update

    The github.com/cloudflare/circl module is updated to v1.6.3 in Crossplane v2.0.8.

  • securityThe OTLP HTTP trace exporter module update

    The go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module is updated to v1.43.0 in Crossplane v2.0.8.

  • securityThe github.com/go-jose/go-jose/v4 module update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in Crossplane v2.0.8.

  • securityThe Go version update to 1.25.9

    Go is updated to 1.25.9 in Crossplane v2.0.8.

  • securityThe github.com/go-git/go-git/v5 module update to v5.17.1

    The github.com/go-git/go-git/v5 module is updated to v5.17.1 in Crossplane v2.0.8.

  • securityThe github.com/moby/spdystream module update

    The github.com/moby/spdystream module is updated to v0.5.1 in Crossplane v2.0.8.

  • securityThe github.com/docker/cli module update

    The github.com/docker/cli module is updated to v29.2.0+incompatible in Crossplane v2.0.8.

  • securityThe github.com/sigstore/timestamp-authority/v2 module update

    The github.com/sigstore/timestamp-authority/v2 module is updated to v2.0.6 in Crossplane v2.0.8.

  • securityThe github.com/go-git/go-git/v5 module update to v5.18.0

    The github.com/go-git/go-git/v5 module is updated to v5.18.0 in Crossplane v2.0.8.

Source
Crossplanev1.20.6Orchestration & ManagementApr 20, 2026

Crossplane v1.20.6 is a dependency-focused release with updates to several Go modules, including security-marked changes. It also includes an update to crossplane-runtime v1.20.6.

Action needed (5)

  • securityThe github.com/cloudflare/circl module, updated to v1.6.3

    The github.com/cloudflare/circl module is updated to v1.6.3 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module, updated to v1.43.0

    The go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module is updated to v1.43.0 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.17.1

    The github.com/go-git/go-git/v5 module is updated to v5.17.1 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe github.com/moby/spdystream module, updated to v0.5.1

    The github.com/moby/spdystream module is updated to v0.5.1 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.18.0

    The github.com/go-git/go-git/v5 module is updated to v5.18.0 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

Source
Backstagev1.50.2CI/CD & App DeliveryApr 18, 2026

This release combines a new TechDocs sidebar styling capability with dependency updates and constraints. It also corrects an active tab indicator issue in Backstage UI.

Action needed (1)

  • breakingReact Aria dependency ranges constrained to patch-only updates

    React Aria dependency ranges are limited to patch-only updates in Backstage v1.50.2.

Source
Daprv1.15.14Orchestration & ManagementApr 16, 2026

This is a security-focused maintenance release. It corrects a service-invocation ACL mismatch caused by path normalization and updates Go to v1.25.9 for CVE coverage.

Action needed (2)

  • securityNormalized service-invocation ACL and outbound dispatch paths

    The normalized path form is used for both the ACL check and outbound dispatch, removing the mismatch in service invocation.

  • securityThe Go dependency, updated to v1.25.9

    The Go dependency is updated to v1.25.9 to address CVEs affecting the 1.24 line.

Source
Daprv1.17.5Orchestration & ManagementApr 16, 2026

This release contains a security fix for service-invocation access-control policy handling. It aligns method-path normalization for ACL checks and outbound dispatch, which concerns operators using these policies.

Action needed (1)

  • securityService-invocation ACL path normalization

    In Dapr v1.17.5, the normalized method path is used for both the service-invocation ACL check and outbound dispatch, eliminating the mismatch that caused the bypass.

Source
Daprv1.16.14Orchestration & ManagementApr 16, 2026

A security-focused release fixes a service-invocation ACL bypass caused by inconsistent path normalization. It also rejects dangerous method-path characters, removes the purell dependency from ACL path handling, and applies additional path cleaning in constructRequest.

Action needed (3)

  • securityConsistent service-invocation method path normalization

    Method paths are normalized at the service invocation edge for HTTP and gRPC public API calls, gRPC internal calls, and proxied calls. The normalized form is used for both the ACL check and outbound dispatch.

  • securityStricter method path validation

    Normalization uses path.Clean to resolve ../ segments and duplicate slashes. Method paths containing #, ?, null bytes, or control characters are rejected.

  • securityThe purell dependency, removed from the ACL path

    The purell dependency has been removed from ACL path handling.

Source
Ciliumv1.19.3Networking & MessagingApr 15, 2026

Cilium v1.19.3 combines operator-relevant bug fixes with configuration and CLI additions, along with dependency and image updates. The release is relevant to deployments using the affected functionality and to users tracking dependency changes.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 module update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in the v1.19.3 release. The update is marked as security-related.

Source
Ciliumv1.18.9Networking & MessagingApr 15, 2026

Cilium v1.18.9 contains correctness fixes and dependency updates. It also includes security-related changes, including an injection-prevention fix and a security-tagged module update.

Action needed (2)

  • securityRegex dollar-sign escaping for injection prevention

    Regex handling now escapes the $ character to prevent injection. The fix ships in Cilium v1.18.9.

  • securityThe github.com/go-jose/go-jose/v4 dependency update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in Cilium v1.18.9. The release note marks this dependency update as security-related.

Source
Keycloak26.6.1SecurityApr 15, 2026

Keycloak 26.6.1 is a maintenance release with two described security fixes in the core. It also contains dependency updates, an enhancement, and bug fixes.

Action needed (2)

  • securitymediumCVE-2026-4366, blind server-side request forgery via HTTP redirect handling

    Keycloak 26.6.1 fixes blind server-side request forgery through HTTP redirect handling in core.

  • securitylowCVE-2026-4633, user enumeration via identity-first login

    Keycloak 26.6.1 fixes user enumeration through identity-first login in core.

Source
Daprv1.16.13Orchestration & ManagementApr 15, 2026

Dapr v1.16.13 includes a security-relevant Go dependency update and correctness fixes. The release also changes scheduler reliability and Pulsar pub/sub processing behavior.

Action needed (1)

  • securityThe Go version update

    The Go version is updated from 1.25.8 to 1.25.9 in v1.16.13.

Check if affected (1)

  • breakingprocessMode initialization validation

    Applies if you configure processMode.

Source
Litmus3.28.0ObservabilityApr 15, 2026

A maintenance release with several defect fixes, including prevention of stale configuration leakage and a frontend base-image update to address a Python vulnerability. It also includes fixes for workflow event handling, branding, and experiment image-registry behavior.

Action needed (2)

  • securityStale configuration across probes of the same type

    Stale configuration no longer leaks across multiple probes of the same type.

  • securityFrontend base image updated to ubi9

    The frontend base image is updated to ubi9 to resolve a Python vulnerability.

Source
Rookv1.19.4Storage & DataApr 14, 2026

This release combines an operator defect correction with changes to operator capabilities, configuration, and dependency or image versions. It contains no security advisories or explicitly described security fixes.

Action needed (1)

  • breakingThe default COSI sidecar image version, updated

    The default version of the COSI sidecar image is updated in the COSI component.

Source
Backstagev1.50.0CI/CD & App DeliveryApr 14, 2026

A substantial feature and maintenance release with API, UI, plugin, authentication-token, catalog, scaffolder, frontend, and SCM changes. It also updates vulnerable glob and rollup dependencies, fixes the .well-known/oauth-protected-resource URL, and includes broad correctness and dependency updates.

Action needed (4)

  • securityhighThe glob and rollup dependencies, upgraded

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions. rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe glob dependency, upgraded to v13

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.

  • securityThe rollup dependency, upgraded to v4.59+

    rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe .well-known/oauth-protected-resource URL

    The .well-known/oauth-protected-resource resource URL was fixed to comply with RFC 9728 Section 7.3. Dynamic resource paths are enabled.

Check if affected (22)

  • breakingThe auth.omitIdentityTokenOwnershipClaim setting

    Applies if you do not configure auth.omitIdentityTokenOwnershipClaim.

  • breakingThe SignInResolverFactoryOptions type parameters

    Applies if you use SignInResolverFactoryOptions.

  • breakingThe catalog permission exports, removed

    Applies if you use CatalogPermissionRuleInput, CatalogPermissionExtensionPoint, or catalogPermissionExtensionPoint.

  • + 19 more on the release page

Plan ahead (6)

  • deprecatedThe show and showModal compatibility implementation, deprecated

    Applies if you use show or showModal.

  • deprecatedThe auth.omitIdentityTokenOwnershipClaim setting, deprecatedremoval date not announced

    Applies if you configure auth.omitIdentityTokenOwnershipClaim.

  • deprecatedThe config.schema callback format, deprecated

    Applies if you use config.schema.

  • + 3 more on the release page
Source
containerdv2.2.3Kubernetes CoreApr 14, 2026

containerd v2.2.3 includes a disclosed security-related update to spdystream, alongside correctness, runtime, extraction, and dependency/toolchain changes. The recorded advisory is CVE-2026-35469.

Action needed (1)

  • securityhighspdystream dependency update for CVE-2026-35469

    The spdystream dependency is updated in containerd v2.2.3 in connection with CVE-2026-35469.

Source
containerdv2.0.8Kubernetes CoreApr 14, 2026

containerd v2.0.8 is a maintenance release with security fixes, a CNI restart correction, and dependency and toolchain updates. The security changes concern spdystream and credential handling in CRI pod events.

Action needed (1)

  • securityhighThe spdystream update for CVE-2026-35469

    The spdystream security update for CVE-2026-35469 ships in containerd v2.0.8.

Check if affected (1)

  • securityCredential sanitization before gRPC returns

    Applies if you use pod events through the Container Runtime Interface (CRI).

Source
containerdv2.1.7Kubernetes CoreApr 14, 2026

A maintenance release with fixes across CRI, runtime, image distribution, and security-sensitive paths. It also updates dependencies and toolchains, including a spdystream security update and a fix for credential leakage.

Action needed (2)

  • securityhighCVE-2026-35469 and GHSA-pc3f-x583-g7j2

    The release includes CVE-2026-35469 and GHSA-pc3f-x583-g7j2, related to the spdystream security fix.

  • securityhighgithub.com/moby/spdystream v0.5.1 update

    The release updates github.com/moby/spdystream to v0.5.1. The update carries fixes associated with CVE-2026-35469 and GHSA-pc3f-x583-g7j2.

Check if affected (1)

  • securityCredential sanitization before gRPC returns

    Applies if pod events are used.

Source
← NewerOlder →
Browse by month