RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Apr 2026Clear ×
NATSv2.12.8Networking & MessagingApr 27, 2026

A maintenance release with a security fix, correctness fixes, a performance improvement, and dependency and toolchain manifest updates. Most changes take effect through the release itself without additional operator action.

Action needed (1)

  • securityBearer JWT disclosure fix in /connz

    The /connz monitoring endpoint no longer discloses bearer JWTs. The fix ships in the NATS monitoring endpoint.

Source
NATSv2.11.17Networking & MessagingApr 27, 2026

A maintenance release updates the Go toolchain and corrects NATS server defects. It includes fixes for bearer credential disclosure through monitoring and for redaction of route and cluster URL secrets.

Check if affected (2)

  • securityThe /connz endpoint no longer discloses bearer JWTs

    Applies if you use the /connz monitoring endpoint.

  • securityMonitoring redaction of route and cluster URL secrets

    Applies if you pass route and cluster URL secrets as command line arguments.

Source
Envoyv1.38.0Networking & MessagingApr 23, 2026

A release with breaking configuration and flag changes, many new extension and protocol capabilities, and fixes for security, correctness, and observability. The recorded additions include module and filter extension APIs, MCP and A2A protocol support, OpenSSL builds, new formatters and metrics, and expanded streaming and TLS capabilities.

Action needed (1)

  • securityhighnghttp2 **CVE-2026-27135** patch

    The nghttp2 **CVE-2026-27135** patch is included.

Check if affected (6)

  • securityURL encoding for query_parameter_mutations values

    Applies if you configure query_parameter_mutations.

  • securityRBAC concatenation-based bypass prevention

    Applies if RBAC runs.

  • breakingExplicit max_early_data_bytes configuration

    Applies if you configure upstream_connect_mode with a value other than IMMEDIATE and do not configure max_early_data_bytes.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedThe enforce_rsa_key_usage option, deprecatedremoval date not announced

    Applies if you configure enforce_rsa_key_usage.

Source
Contourv1.33.4Networking & MessagingApr 20, 2026

A release with a fix for Lua code injection, a required Envoy version change, and an Envoy dependency update. It is tested against Kubernetes 1.32 through 1.34.

Check if affected (2)

  • securityhighCVE-2026-41246 fix for cookieRewritePolicies[].pathRewrite.value

    Applies if you use HTTPProxy resources.

  • breakingEnvoy 1.35.0 minimum version

    Applies if you depend on Envoy.

Source
Contourv1.32.5Networking & MessagingApr 20, 2026

Contour v1.32.5 fixes a Lua code injection vulnerability and upgrades Envoy to v1.34.14. The release also includes an informational Kubernetes compatibility update.

Action needed (1)

  • securityhighCVE-2026-41246 Lua code injection vulnerability fixed

    This release fixes CVE-2026-41246 and GHSA-x4mj-7f9g-29h4, a Lua code injection vulnerability affecting cookieRewritePolicies[].pathRewrite.value.

Source
Contourv1.31.6Networking & MessagingApr 20, 2026

This release fixes a Lua code injection vulnerability in Contour's Cookie Rewriting feature and updates Envoy to v1.34.14. It is tested against Kubernetes 1.30 through 1.32.

Check if affected (1)

  • securityhighLua code injection fix for CVE-2026-41246

    Applies if you configure cookieRewritePolicies[].pathRewrite.value.

Source
Ciliumv1.19.3Networking & MessagingApr 15, 2026

Cilium v1.19.3 combines operator-relevant bug fixes with configuration and CLI additions, along with dependency and image updates. The release is relevant to deployments using the affected functionality and to users tracking dependency changes.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 module update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in the v1.19.3 release. The update is marked as security-related.

Source
Ciliumv1.18.9Networking & MessagingApr 15, 2026

Cilium v1.18.9 contains correctness fixes and dependency updates. It also includes security-related changes, including an injection-prevention fix and a security-tagged module update.

Action needed (2)

  • securityRegex dollar-sign escaping for injection prevention

    Regex handling now escapes the $ character to prevent injection. The fix ships in Cilium v1.18.9.

  • securityThe github.com/go-jose/go-jose/v4 dependency update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in Cilium v1.18.9. The release note marks this dependency update as security-related.

Source
NATSv2.12.7Networking & MessagingApr 14, 2026

A maintenance release with a dependency and toolchain update, configuration constraint changes, performance improvements, and correctness fixes. It also fixes an ACL permission bypass along with issues affecting leaf connections, streams, storage, and client authentication.

Check if affected (3)

  • securityQueue subscription enforcement of ACL deny patterns

    Applies if you use queue subscriptions and configure non-queue ACL deny patterns.

  • breakingThe no_auth_user configuration field, restricted to client connections

    Applies if you configure no_auth_user.

  • breakingDuplicate INFO permission updates for solicited leaf connections

    Applies if you use solicited leaf connections.

Source
Browse by month