A security-fix release with fixes for multiple CVEs and updates to affected dependencies. It also changes the default HTTP behavior and restricts configmap access for namespaced policies.
Action needed (12)
securitycriticalCVE-2025-68121 fix
This release fixes CVE-2025-68121.
securitycriticalCVE-2026-33186 fix
This release fixes CVE-2026-33186.
securityhighCVE-2026-24051 fix
This release fixes CVE-2026-24051 in the 1.16 release line.
securityhighThe
github.dependency updatecom/docker/cli The
github.dependency is updated to resolve CVE-2025-15558.com/docker/cli securityhighCVE-2025-66564 fix
This release resolves CVE-2025-66564.
securitymediumThe
sigstore/rekordependency update tov1.5. 1 The
sigstore/rekordependency is updated tov1.to fix CVE-2026-23831.5. 1 securitymediumThe
go-tuf/v2dependency update tov2.3. 1 The
go-tuf/v2dependency is updated tov2.to address CVE-2026-23992.3. 1 securitymediumCVE-2026-22772 fix
This release fixes CVE-2026-22772.
securitymediumThe
go-tuf/v2dependency update tov2.4. 1 The
go-tuf/v2dependency is updated tov2.to patch CVE-2026-24686.4. 1 securitylowCVE-2026-1229 fix
This release fixes CVE-2026-1229 in the 1.16 release line.
securitylowCVE-2026-26958 fix
This release fixes CVE-2026-26958.
securityStandard library CVE fixes
This release fixes standard library CVEs.
Check if affected (3)
securitycriticalHTTP disabled by default in namespaced policies
Applies if you configure namespaced policies.
securityCVE fixes for
go < 1.25. 8 Applies if you depend on
go < 1..25. 8 breakingRestricted
configmapaccess for namespaced policiesApplies if you configure namespaced policies.