A maintenance release tested against Kubernetes 1.32 through 1.34, with runtime resource tuning and a correction to load balancer status handling. It also updates Go to v1.25.7.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
Contour v1.32.3 updates the Go dependency, corrects an HTTPProxy CRD schema defect, and documents the Kubernetes versions tested with the release. No individual change details are available here.
Source ↗Contour v1.31.4 updates the Go toolchain to v1.24.13 and corrects an HTTPProxy status schema defect that affected load balancer status updates. It is tested against Kubernetes 1.30 through 1.32, and no security advisories are disclosed.
Source ↗Nothing here needs operator attention.
Source ↗A maintenance release with two security fixes and a deprecated KafkaUser API field that requires migration. It also includes API conversion fixes, broker certificate output changes, and dependency and container image updates.
Action needed (1)
securityhighCVE-2026-27133 and CVE-2026-27134 security fixes
The release includes security fixes for CVE-2026-27133 and CVE-2026-27134.
Plan ahead (1)
deprecatedThe
.field is deprecatedspec. authorization. acls[]operation Applies if you configure
..spec. authorization. acls[]operation
This release focuses on dependency and component upgrades. It adds no new operator capabilities or stated security changes, and it requires no setup changes beyond upgrading.
Source ↗Cilium v1.19.1 contains routine bug fixes, performance improvements, and dependency and image updates. The available release information does not identify security advisories or explicitly described security flaws.
Source ↗A maintenance release focused on security fixes, validation, and authorization changes across Istio control-plane and endpoint handling. It also includes operator-facing capability changes and corrections for other defects.
Action needed (1)
securityhighCVE-2025-61732 cgo comment parsing flaw
This release fixes a discrepancy between Go and C/C++ comment parsing that allowed code smuggling into the resulting cgo binary.
Check if affected (4)
securitycriticalCVE-2025-68121 TLS session resumption validation
Applies if you use
Config.with mutations orClone Config..GetConfigForClient securityGateway deployment controller resource validation
Applies if the gateway deployment controller runs.
securityResource annotation validation against container injection
Applies if you configure resource annotations.
- + 1 more on the release page
A security release addressing two vulnerabilities in cgo comment parsing and crypto/tls session resumption. The fixes are relevant to deployments using the affected Go functionality.
Action needed (2)
securitycriticalCVE-2025-68121 session resumption vulnerability correction
CVE-2025-68121 corrects a
crypto/tlssession resumption flaw that could let resumed handshakes succeed afterClientCAsorRootCAschanged between the initial and resumed handshake.securityhighCVE-2025-61732 code-smuggling vulnerability correction
CVE-2025-61732 addresses a discrepancy in Go and C/C++ comment parsing that allowed code smuggling into the resulting cgo binary.
A broad release adds operator-visible capabilities across ambient networking, telemetry, Gateway API, and traffic management, while changing several defaults. The most consequential operational changes affect ambient mesh DNS and iptables behavior, debug endpoint authorization, Envoy metrics compression, and istiod memory and circuit-breaker handling.
Action needed (1)
breakingAutomatic GOMEMLIMIT setting for istiod
istiodnow automatically setsGOMEMLIMITto 90% of its memory limits through theautomemlimitlibrary. The change ships in 1.29.0.
Check if affected (4)
breakingDefault-enabled iptables reconciliation
Applies when the
istio-cniDaemonSet is upgraded.breakingDefault authorization for debug endpoints
Applies if you use debug endpoints on port
15014.breakingDefault HTTP compression for Envoy metrics
Applies if you use Envoy metrics at the Prometheus stats endpoint based on client
Accept-Headervalues.- + 1 more on the release page
A maintenance release combining an operator-facing configuration adjustment with bug fixes and routine dependency and image refreshes. No security advisories or security-specific fixes are disclosed.
Action needed (1)
breakingExclusion of
topology.labels from security labels by defaultkubernetes. io The default security-label handling in this release excludes
topology.labels from security labels.kubernetes. io
This release is focused on dependency and container image maintenance, including a runtime dependency addition and updated installation image digests. No security issues or operator configuration changes are disclosed.
Source ↗This release includes security safeguards for gateway resource creation and pod specification rendering, along with stricter authorization for debug endpoints. It also adds a Helm configuration field and corrects a TLS configuration mapping.
Action needed (1)
securityResource annotation validation
Resource annotation validation now rejects newline and control characters that could inject containers into pod specifications through template rendering.
Check if affected (2)
securityGateway deployment controller resource validation
Applies if the
gateway deployment controllerruns.breakingNamespace-based authorization for debug endpoints
Applies if you use debug endpoints on port
15014.
A maintenance release with defect fixes and compatibility updates across the language integrations, plus changes to Python packaging and logging.
Source ↗A substantial operator-facing feature and maintenance release with new DNS proxy, installation, configuration, API, metric, and datapath capabilities. It also changes defaults and compatibility requirements, removes deprecated interfaces, migrates BGP APIs, and updates security-related dependencies.
Action needed (15)
securityThe
github.dependency, updatedcom/containerd/containerd The
github.module is updated to v1.7.29.com/containerd/containerd securityThe
github.dependency, updatedcom/go-viper/mapstructure/v2 The
github.module is updated to v2.4.0.com/go-viper/mapstructure/v2 securityThe
github.dependency, updatedcom/docker/docker The
github.module is updated to v28.3.3+incompatible.com/docker/docker securityThe
golang.dependency, updatedorg/x/crypto The
golang.module is updated to v0.45.0.org/x/crypto securityThe
helm.dependency, updated to v3.18.4sh/helm/v3 The
helm.module is updated to v3.18.4.sh/helm/v3 securityThe
helm.dependency, updated to v3.18.5sh/helm/v3 The
helm.module is updated to v3.18.5.sh/helm/v3 breakingThe
plpmtuddefault, set toblackholeThe default
plpmtudmode is nowblackhole(blackhole-detected).breakingThe
AddressScopeMaxdefault, set to 254The default
AddressScopeMaxis changed to 254, the host scope, for GKE metadata server and HCP use cases. The related setting is--local-max-addr-scope.breakingThe
tls authModedefault, set tomigrationtls authModeis set tomigrationby default.breakingThe CNI deletion timeout, reduced to 1.5 seconds
The CNI deletion timeout is reduced to 1.5 seconds.
breakingThe
policy-default-local-clusterdefaultpolicy-default-local-clusteris now set by default.breakingHost firewall bypass, disabled by default
Host firewall bypass is disabled by default.
breakingFQDN match pattern sanitization
FQDN match pattern sanitization is refactored and tightened.
breakingEncrypted traffic forwarding via
cilium_host, removedForwarding encrypted traffic via
cilium_hosthas been removed.breakingCNI configuration in the container image, removed
The CNI configuration is no longer installed in the container image.
Check if affected (30)
breakingLocal-cluster default for network policy selectors
Applies if you do not set
clusterin network policy selectors.breakingThe
CiliumBGPPeeringPolicyv1 API, removedApplies if you use
CiliumBGPPeeringPolicy.breakingMutual Authentication, disabled by default
Applies if you enable Mutual Authentication.
- + 27 more on the release page
Plan ahead (7)
deprecated
--enable-ipsec-encrypted-overlay, deprecatedremoval date not announcedApplies if you use
--enable-ipsec-encrypted-overlay.deprecatedKafka match fields and
ToRequiresandFromRequires, deprecatedApplies if you use
ToRequiresorFromRequires.deprecatedTLS certificate and key Helm values, deprecated
Applies if you pass TLS certificates or keys in Helm values.
- + 4 more on the release page