containerd v2.0.8 is a maintenance release with security fixes, a CNI restart correction, and dependency and toolchain updates. The security changes concern spdystream and credential handling in CRI pod events.
Action needed (1)
securityhighThe
spdystreamupdate for CVE-2026-35469The
spdystreamsecurity update for CVE-2026-35469 ships in containerd v2.0.8.
Check if affected (1)
securityCredential sanitization before
gRPCreturnsApplies if you use pod events through the
Container Runtime Interface (CRI).The
Container Runtime Interface (CRI)path sanitizes errors beforegRPCreturns them, preventing credential leaks in pod events. The correction ships in containerd v2.0.8.