A release with operator-facing fixes, new capabilities, API and configuration changes, and dependency updates. It also includes fixes for CVE-2026-32597 in PyJWT and CVE-2026-30922 in pyasn1.
Action needed (3)
securityhighCVE-2026-32597
PyJWTvalidation fixPyJWTcrit header validation was fixed for CVE-2026-32597.securityhighCVE-2026-30922
pyasn1fixThe
pyasn1dependency was updated to address CVE-2026-30922 and its denial-of-service vulnerability.breakingRequired
MaxReplicasfieldMaxReplicasis now required and must use theint32type.
Check if affected (2)
breakingRemoval of the scheduler
cert-hashrestart annotationApplies if you configure
cert-hash.breaking
PYTHONPATHblocked by ISVC and ServingRuntime webhooksApplies if you configure
PYTHONPATH.