Helm v3.21.2 is a patch release that updates its Kubernetes client-library dependency set to v1.36. The release concerns compatibility with the expected Kubernetes v1.36 libraries, including client-go and related components.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release that changes several defaults, updates dependencies, and fixes multiple security vulnerabilities. It also includes a fallback to scp for remote sources and destinations in auto mode.
Check if affected (5)
securitycritical
containerdv2.3.2 security fixesApplies if you use
containerd.securityhighCVE-2026-53657 and GHSA-2j9v-p4xj-cjw2 guest agent socket fix
Applies if you run a QEMU VM that uses the guest agent socket.
breaking
containerd.default on non-Linux guestsuser Applies if you run non-Linux guests.
- + 2 more on the release page
containerd v2.1.9 includes security fixes alongside checkpoint-restore and image-label behavior changes, plus updates to bundled runc and the Go toolchain. The security fixes require the v2.1.9 release, while the other changes matter when their affected behavior is in use.
Action needed (5)
securitycriticalCVE-2026-53488 security fix
The CVE-2026-53488 security issue is corrected in containerd v2.1.9 and is tracked as GHSA-xhf5-7wjv-pqxp.
securityhighCVE-2026-53492 security fix
The CVE-2026-53492 security issue is corrected in containerd v2.1.9 and is tracked as GHSA-33vj-92qq-66hc.
securityhighCVE-2026-53489 security fix
The CVE-2026-53489 security issue is corrected in containerd v2.1.9 and is tracked as GHSA-rgh6-rfwx-v388.
securitymediumCVE-2026-50195 security fix
The CVE-2026-50195 security issue is corrected in containerd v2.1.9 and is tracked as GHSA-cvxm-645q-p574.
securitymediumCVE-2026-47262 security fix
The CVE-2026-47262 security issue is corrected in containerd v2.1.9 and is tracked as GHSA-jpcc-p29g-p8mq.
containerd v1.7.33 includes security updates for containerd and go-jose, along with runtime and toolchain dependency updates. It also changes file-read bounds and image-config label propagation.
Action needed (2)
securitycritical
containerdsecurity updates for CVE-2026-53488 and CVE-2026-47262containerdships security updates associated with CVE-2026-53488 and CVE-2026-47262. The release also includes GHSA-jpcc-p29g-p8mq and GHSA-xhf5-7wjv-pqxp.securityhigh
go-jose/go-jose/v3updated to v3.0.5go-jose/go-jose/v3is updated to v3.0.5 to fix GHSA-78h2-9frx-2jm8 and CVE-2026-34986.
This release includes containerd security changes, behavior changes, and updates to the bundled runc binary and Go toolchain. The security advisories and runtime updates concern deployments that use the affected container runtime components.
Action needed (1)
securitycritical
containerdsecurity fixes, including CVE-2026-53488The
containerdchange is associated with CVE-2026-53488, CVE-2026-47262, GHSA-jpcc-p29g-p8mq, and GHSA-xhf5-7wjv-pqxp.
containerd v2.3.2 is a maintenance release with disclosed security fixes, correctness and behavior changes, and dependency and toolchain updates. The security fixes are the main concern for operators, while the other changes matter where the affected behavior is in use.
Action needed (1)
securitycriticalThe
containerdsecurity fixescontainerdv2.3.2 includes a security fix identified as CVE-2026-50195 and associated with CVE-2026-47262, CVE-2026-53488, CVE-2026-53489, CVE-2026-53492, GHSA-33vj-92qq-66hc, GHSA-cvxm-645q-p574, GHSA-jpcc-p29g-p8mq, GHSA-rgh6-rfwx-v388, and GHSA-xhf5-7wjv-pqxp.
A maintenance release with disclosed security fixes, dependency and toolchain updates, and changes to checkpoint and image-processing behavior. User-database reads are bounded in openUserFile, which may reject inputs that previously worked.
Action needed (2)
securitycriticalSecurity fixes for five disclosed CVEs
The release includes fixes for CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262, along with the associated GHSA-33vj-92qq-66hc, GHSA-cvxm-645q-p574, GHSA-jpcc-p29g-p8mq, GHSA-rgh6-rfwx-v388, and GHSA-xhf5-7wjv-pqxp advisories.
breakingBounded
openUserFileuser-database readsUser-database file reads in
openUserFileare now bounded, so inputs that previously worked may be rejected.
A maintenance release with a correctness fix in WaitForDelete. The status observer no longer cancels the watch too early, which addresses intermittent failures in full test suites.
Helm v4.2.1 is a maintenance release with correctness fixes and dependency updates. It includes an update to golang. that addresses GO-2026-5026.
Action needed (1)
securitycriticalThe
golang.dependency update fororg/x/net GO-2026-5026Helm v4.2.1 updates
golang.to v0.55.0 to addressorg/x/net GO-2026-5026.
Helm v3.21.1 includes dependency and toolchain updates alongside fixes for correctness issues. The disclosed dependency update affects releases using golang..
Action needed (1)
securitycriticalThe
golang.dependency, updated fororg/x/net GO-2026-5026Helm v3.21.1 bumps
golang.toorg/x/net v0.to address55. 0 GO-2026-5026.
A maintenance release with Go 1.26.4 build updates and correctness and performance fixes across scheduling, kubelet volume handling, suspended Jobs, Secret data, endpoint processing, and kubeadm dry-run certificate copying. No security advisories are disclosed.
Source ↗A maintenance release with correctness and performance fixes, along with an updated Go toolchain dependency. The recorded notes do not disclose security advisories or security-specific flaws.
Source ↗A maintenance release with a Go 1.25.11 toolchain update and fixes for several operator-facing defects. The listed fixes address controller, storage, node, and kubeadm behavior.
Source ↗A maintenance release updates the Go build dependency to Go 1.25.11 and fixes an endpoint-controller panic when processing services with an empty IPFamilies field. No other operator action is indicated by the available release details.
A release with new plugin capabilities, stricter validation, DNS and cache behavior changes, expanded platform support, and malformed-input handling fixes. The HTTP/3 request header limit is narrowed for DoH3.
Check if affected (1)
breakingBound
DoH3HTTP/3 request header sizeApplies if you use
DoH3.
Nothing here needs operator attention.
Source ↗A maintenance release fixes container status ImageRef changes after CRI-O restarts and reduces debug-log verbosity for List* RPC calls. No other operator-facing changes are described.
cri-o v1.34.9 fixes two correctness defects. The remaining listed headings do not describe operator-facing changes.
Source ↗A maintenance release fixes a race condition where cri-o reports exitCode 255 when a container exits fast. Nothing else here needs operator attention.
containerd v2.1.8 includes a disclosed security correction identified by CVE-2026-46680 and GHSA-fqw6-gf59-qr4w. The release also contains operator-facing runtime and snapshotter changes in its broader changelog.
Action needed (1)
securityhighCVE-2026-46680 security correction
containerd v2.1.8 includes a correction for CVE-2026-46680, associated with GHSA-fqw6-gf59-qr4w.
A maintenance release expands maintenance-status access to non-admin users, corrects unexpected learner promotion and data-file-path validation issues, and compiles binaries with Go 1.25.10. The bug fixes require no operator action beyond upgrading, while the access change matters to operators relying on the previous restriction.
Source ↗A maintenance release with correctness fixes and dependency updates. The golang. update addresses GO-2026-5026.
Action needed (1)
securitycriticalThe
golang.dependency update fororg/x/crypto GO-2026-5026The
golang.dependency is updated toorg/x/crypto v0.to address52. 0 GO-2026-5026.
A maintenance release that ends support for the v3. line and updates the Go toolchain used to compile binaries. No further patches will be issued for v3..
Plan ahead (1)
deprecatedThe
v3.line, end of support4
A feature and maintenance release with CLI and template changes, QEMU behavior updates, and fixes across drivers, hostagent, shell, and guest support. It also includes a deprecation, while no security advisories or explicitly described vulnerabilities are present.
Check if affected (1)
breaking
QEMU2MBOVMFimages dropped by openSUSEApplicability is not stated in the release notes.
Plan ahead (1)
deprecatedThe
_LIMA_QEMU_UEFI_IN_BIOSflag, deprecatedApplies if you configure
_LIMA_QEMU_UEFI_IN_BIOS.