A security and maintenance release with authorization-bypass fixes and dependency updates that address reported vulnerabilities. It also includes correctness fixes, with no operator configuration changes or deprecations announced.
Action needed (4)
securitycritical
google.updated togolang. org/grpc 1.79. 3 The release updates
google.togolang. org/grpc 1.to resolve CVE-2026-33186.79. 3 securityhighAuthorization bypasses in multiple APIs, CVE-2026-33413
The etcd server fixes authorization bypasses in multiple APIs. The issue is identified by CVE-2026-33413 and GHSA-q8m4-xhhv-38mg.
securityhigh
go.updated toopentelemetry. io/otel/sdk v1.40. 0 The release updates
go.toopentelemetry. io/otel/sdk v1.. The update addresses40. 0 GO-2026-4394.securityhigh
golang.updated toorg/x/net v0.51. 0 The release updates
golang.toorg/x/net v0.to resolve51. 0 GO-2026-4559.
Check if affected (1)
securitylowRBAC checks for nested etcd transactions, CVE-2026-33343
Applies if you use nested etcd transactions and
RBAC.