cert-manager v1. changes permissions in the cert-manager-edit aggregate ClusterRole and updates the Go toolchain. Workflows that directly create or modify Challenge or Order resources may require explicit permissions after the release.
Action needed (2)
securityhigh
Gov1.with fixes for CVE-2026-27145, CVE-2026-42504, and CVE-2026-4250725. 11 Gois updated tov1.in cert-manager25. 11 v1.to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507.19. 6 security
Go1.dependency upgrade25. 10 Gois upgraded to1.as part of the dependency updates in cert-manager25. 10 v1..19. 6
Check if affected (1)
securityReduced
cert-manager-editpermissions forChallengeandOrdercreation and updatesApplies if you use the
cert-manager-editaggregate ClusterRole for workflows that create or modifyChallengeorOrderresources.The
cert-manager-editaggregate ClusterRole no longer includes thecreate,patch, orupdateverbs forChallengeandOrder. This change ships in cert-managerv1.and addresses GHSA-8rvj-mm4h-c258.19. 6