RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Sep 2026Clear ×
CRI-Ov1.37.0Kubernetes CoreYesterdaySep 15, 2026

A substantial feature and compatibility release for operators, with changed defaults and interfaces alongside correctness and performance improvements. It also includes identified security fixes and refreshes a broad set of dependencies.

Action needed (2)

  • securityhighThe CVE-2026-15809 /etc/passwd injection fix

    CRI-O fixes CVE-2026-15809, which allowed a bypass of the CVE-2022-4318 fix and /etc/passwd injection through newline characters in the HOME environment variable.

  • securityhighThe Go toolchain, updated to 1.26.4

    The Go toolchain is updated to 1.26.4 to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507.

Check if affected (4)

  • breakingThe insecure_registries option and --insecure-registry flag, removed

    Applies if you configure insecure_registries or use --insecure-registry.

  • breakingThe container_level_enabled default, changed to checkpoint_only

    Applies if you do not configure container_level_enabled.

  • breakingThe gRPC message size defaults, reduced to 16 MiB

    Applies if grpc_max_send_msg_size or grpc_max_recv_msg_size is not configured.

  • + 1 more on the release page
Source
Helmv4.3.0Kubernetes CoreSep 9, 2026

A feature release adding new Helm capabilities and output options, alongside correctness fixes and performance improvements. It also includes dependency updates with two disclosed security-related bumps.

Action needed (3)

  • securitycriticalgolang.org/x/net update for GO-2026-5026

    Helm updates golang.org/x/net to v0.55.0 to address GO-2026-5026.

  • securitymediumgo.opentelemetry.io/otel update for GO-2026-5158

    Helm updates go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158.

  • breakingPer-file decompression size limit removal

    Helm removes the per-file decompression size limit from file decompression.

Check if affected (1)

  • breakingOwnership verification before resource deletion

    Applicability is not stated in the release notes.

Source
containerdv1.7.35Kubernetes CoreSep 4, 2026

A security-focused maintenance release with fixes for vulnerabilities and changes to image fetching and Windows log handling. Runtime and performance improvements are also included.

Action needed (2)

Check if affected (1)

  • breakingThe ScrubLogs default on Windows

    Applies if you run on Windows.

Source
containerdv2.0.12Kubernetes CoreSep 4, 2026

A security-focused maintenance release fixes two disclosed vulnerabilities, changes the Windows logging default, and hardens registry fetching. It also includes correctness and performance fixes.

Action needed (2)

  • securityCVE-2026-53495 and GHSA-7jxh-36q5-gcqv security fix

    This release fixes the disclosed vulnerability identified by CVE-2026-53495 and GHSA-7jxh-36q5-gcqv.

  • securityGHSA-rp3h-jf77-q9p4 security fix

    This release fixes the disclosed vulnerability identified by GHSA-rp3h-jf77-q9p4.

Check if affected (1)

  • breakingThe ScrubLogs Windows default

    Applies if you run containerd on Windows.

Source
Browse by month