A release with security corrections, breaking configuration removals, and an output-field rename that may require operator or log-collector changes. It also adds TLS and cache configuration, query and tracing changes, and defect fixes across several Thanos components.
Action needed (1)
securitycritical
thanos-community/grpc-gofork update for CVE-2026-33186The
thanos-community/grpc-gofork is bumped to fix CVE-2026-33186, an authorization bypass via malformed:pathheaders.
Check if affected (4)
security
Receivetenant ID validationApplies if you run
Receive.breaking
Query-Frontendtime_takenfield renamed totime_taken_msApplies if you run
Query-Frontend.breaking
--shipper.flag removedignore-unequal-block-size Applies if you configure
--shipper..ignore-unequal-block-size - + 1 more on the release page