An operator release with expanded configuration and LLMInferenceService capabilities, plus chart and dependency updates, behavior changes, removals, and defect corrections. It also includes security fixes for operators to review.
Action needed (13)
securitycritical
h11malformed-body fix for CVE-2025-43859h11malformed-body handling associated with CVE-2025-43859 is addressed in this release.securityhigh
starletteversion0.49. 1 starletteis pinned to version0.to fix CVE-2025-62727 in this release.49. 1 securityhigh
lightgbmversion4.6. 0 lightgbmis updated to version4.for CVE-2024-43598 in this release.6. 0 securityhighCVE-2025-66418 decompression-chain fix
The unbounded number of links in the decompression chain associated with CVE-2025-66418 is addressed in this release.
securityhigh
expr-lang/exprversionv1.17. 7 expr-lang/expris updated tov1.to fix CVE-2025-68156 in this release.17. 7 securityhigh
cryptographyfix for CVE-2026-26007The
cryptographyissue associated with CVE-2026-26007 is addressed in this release.securityhigh
python-multipartfix for CVE-2026-24486The arbitrary file write issue in
python-multipartassociated with CVE-2026-24486 is addressed in this release.securitymediumFixes for CVE-2025-22872, CVE-2025-47914, and CVE-2025-58181
This release addresses CVE-2025-22872, CVE-2025-47914, and CVE-2025-58181.
security
https.path traversal preventiongo The path traversal issue in
https.is prevented in this release.go securitySeveral CVE fixes
This release addresses several CVEs.
security
AIOHTTPHTTP Parserauto_decompressfixThe
AIOHTTPHTTP Parserauto_decompressfeature issue involving zip bombs is addressed in this release.security
extractTarFilespath traversal fixThe path traversal vulnerability in
extractTarFilesis addressed in this release.breaking
minioreplacement withseaweedfsminiois replaced withseaweedfsin this release.
Check if affected (6)
breaking
inferenceserviceCRD cert-manager annotation removalApplies if you use the
inferenceserviceCRD.breakingPython 3.9 support removal
Applies if you run Python 3.9.
breakingDeprecated
--disable-log-requestsflag removalApplies if you configure
--disable-log-requests.- + 3 more on the release page