RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Sep 2026Clear ×
Keycloak26.7.4SecurityTodaySep 16, 2026

A security-heavy maintenance release with vulnerability fixes, alongside correctness and performance corrections. It also updates the Quarkus dependency.

Action needed (4)

  • securityhighCVE-2026-79651 and unbounded locale caching

    CVE-2026-79651 fixes an unauthenticated denial-of-service issue caused by unbounded locale caching. The fix ships in this release.

  • securityhighCVE-2026-74909 and matrix parameter stripping

    CVE-2026-74909 completes the fix for a percent-encoded semicolon bypass of matrix parameter stripping in PathMatcher. The fix ships in this release.

  • securityhighCVE-2026-17526 and the impersonation role

    CVE-2026-17526 fixes privilege escalation involving the impersonation role impersonating a realm administrator. The fix ships in this release.

  • securitymediumCVE-2026-19607 and username takeover

    CVE-2026-19607 fixes a username takeover issue that could lead to account lockout. The fix ships in this release.

Check if affected (2)

  • securityhighCVE-2026-18212 and SAML Redirect DEFLATE helpers

    Applies if you use SAML Redirect.

  • securityCVE-2026-90997 and stateless replay gate row counts

    Applies if you use MySQL/MariaDB.

Source
Backstagev1.55.0CI/CD & App DeliveryYesterdaySep 15, 2026

A broad feature and maintenance release adds scaffolder recovery and credential controls, TechDocs, notification and streaming capabilities, and Kubernetes and authentication improvements. It also includes dependency and tooling security updates, a security fix, and compatibility changes that affect users of the listed resolvers, catalog integrations, MCP configuration, and task recovery.

Action needed (6)

  • securityModule Federation dependency updates for security

    This release updates the Module Federation dependencies to versions that avoid known security vulnerabilities.

  • securityYarn tooling dependency updates for security

    This release updates the Yarn tooling dependencies to versions that avoid known security vulnerabilities.

  • securityModule Federation security dependency update

    This release updates the Module Federation dependencies to versions that avoid known security vulnerabilities.

  • securityOpenAPI generator tooling security update

    This release updates the OpenAPI generator tooling to avoid known security vulnerabilities.

  • securityOpenAPI generator tooling security update

    This release updates the OpenAPI generator tooling to avoid known security vulnerabilities.

  • breakingLocale-insensitive Unicode casing

    String handling now uses locale-insensitive Unicode casing for consistent results across environments.

Check if affected (6)

  • securityKubernetes catalog cluster locator URL validation

    Applies if you use the catalog cluster locator.

  • securityPull request workspace handling security fix

    Applies if you use pull request workspace handling.

  • breakingGitHub user ID catalog lookup matching

    Applies if you use GitHub user ID catalog lookups.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedGitHub username sign-in resolver deprecation

    Applies if you use the GitHub username sign-in resolver.

Source
Kyvernov1.19.1SecuritySep 10, 2026

A security-focused maintenance release with dependency updates and fixes for policy and egress behavior. It also includes correctness changes, deprecation warning enforcement, and a narrowed policy constraint that may require operator changes.

Action needed (2)

  • securitycriticalGo and x/net updates for CVE-2026-39821

    The release updates Go to 1.26.6 and x/net to resolve CVE-2026-39821.

  • securityhighGo update for CVE-2026-56853

    The release updates Go to address CVE-2026-56853.

Check if affected (3)

  • securityPolicyException scope bypass fix for GHSA-5cjf-wwfg-pj4c

    Applies if you use the PolicyException CRD.

  • securityapiCall.service egress blocklist bypass fix

    Applies if you configure apiCall.service egress.

  • breakingglobalContext constraint in namespaced policies

    Applies if you use globalContext in namespaced policies.

Source
Kubescapev4.0.13SecuritySep 2, 2026

A broad feature release expands scanning, policy, reporting, remediation, notifications, telemetry, integrations, and output capabilities. It also includes security hardening and stricter scan constraints, alongside many correctness and runtime fixes.

Action needed (2)

  • securityGo dependency security vulnerabilities

    Dependabot fixes security vulnerabilities in Go dependencies shipped with the release.

  • securitygosec SAST findings

    The release remediates gosec SAST findings in the Go codebase.

Check if affected (10)

  • securityGrafeas filtering through resourceURL

    Applies if you run imagescan.

  • breakingClient-supplied account and accessKey in scan requests

    Applies if you use scan requests.

  • breakingHard validation for --include-controls

    Applies if you configure --include-controls.

  • + 7 more on the release page

Plan ahead (1)

  • deprecatedThe --fail-threshold flag, hidden and deprecated

    Applies if you configure --fail-threshold.

Source
Browse by month