This Linkerd release contains dependency version updates. No functional or security changes are stated, and the dependency updates are applied as part of the release without operator setup changes.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
This release updates dependencies and component versions across Linkerd. It also corrects resource labels in policy-k8s outbound indexer logs.
Source ↗grpc v1.81.0 fixes three correctness issues and changes the default state of the error_flatten experiment. It also includes an internal SSL implementation change with no stated operator impact.
A maintenance release with a security fix for invalid HTTPProxy configurations and an update to golang.. It also updates the Go toolchain to 1.25.10 and is tested against Kubernetes 1.32 through 1.34.
Action needed (1)
securitycritical
golang.updated to v0.55.0, CVE-2026-39821org/x/net Contour v1.33.5 updates
golang.to v0.55.0. The change addresses CVE-2026-39821.org/x/net
Check if affected (1)
securitymediumInvalid
HTTPProxyconfiguration rejected, GHSA-g3xr-5w5j-w4q4Applies if you configure
HTTPProxywith afallback certificateand enableJWT verification.
This Linkerd edge release updates the OpenSSL and tower-http dependencies and ships Linkerd proxy version 2.353.0. No functional changes, security advisories, or operator actions are identified.
Source ↗NATS v2.14.1 is a maintenance release with dependency and toolchain updates, monitoring additions, behavioral improvements, and correctness fixes. The release has no security advisories or explicitly described security vulnerabilities.
Source ↗NATS v2.12.9 adds monitoring metrics and broadens acceptance of client TLS certificates with DNS subject alternate names. It also changes several operational behaviors, improves performance, and fixes defects across General, Leafnode, JetStream, Raft, storage, and MQTT functionality. No security advisories or explicitly security-related fixes are disclosed.
Source ↗Emissary v4.1.0 updates the Envoy dependency from 1.36.2 to 1.37.2. It also fixes stale cached entries when an empty-delta snapshot is received, addressing the Istio mTLS certificate-rotation failure described in #4744.
Source ↗A feature release adds Gateway API, ambient-mode, telemetry, Helm, and operability capabilities. Authenticated XDS debug endpoints and the new default image registry are the changes most likely to affect deployment and operational configuration.
Action needed (1)
breakingDefault Istio image registry
The default registry for Istio images is now
registry..istio. io
Check if affected (1)
breakingAuthentication required for XDS debug endpoints
Applies if
ENABLE_DEBUG_ENDPOINT_AUTHis set.
A maintenance release adds Gateway API compatibility, analyzer and HBONE tuning capabilities, and fixes certificate, controller, probe, output, and authorization issues. The authorization fixes address cross-namespace configuration access and regex handling in AuthorizationPolicy.
Action needed (1)
securityCross-namespace access to
istio.andio/debug/syncz istio.io/debug/config_dump Authorization is fixed so an authenticated workload cannot enumerate proxies or retrieve configuration dumps for workloads in other namespaces through
istio.andio/debug/syncz istio..io/debug/config_dump
Check if affected (2)
securityRegex handling in
AuthorizationPolicyidentity fieldsApplicability is not stated in the release notes.
breakingThe
AMBIENT_ENABLE_AWS_BRANCH_ENI_PROBEsetting and kubelet health probesApplies when ambient mesh pods run on AWS EKS and use Security Groups for Pods (branch ENI).
A maintenance release that adds Gateway API v1.4.1 support and new diagnostics and configuration controls while fixing several correctness issues. It also includes two described security fixes for XDS debug endpoint authorization and regex handling in AuthorizationPolicy.
Action needed (1)
securitySame-namespace authorization for
StatusGenXDS debug endpointsThe
StatusGen-served XDS debug endpointsistio.andio/debug/syncz istio.now enforce same-namespace authorization for non-system callers. Authenticated workloads can no longer enumerate proxies or retrieve configuration dumps for workloads in other namespaces.io/debug/config_dump
Check if affected (1)
securityEscaped regex metacharacters in
AuthorizationPolicyidentity fieldsApplies if you configure
source.orprincipals source..namespaces
A release that changes the default sidecar mode and promotes native sidecars to GA. It also fixes correctness issues, adds configurable timestamp handling, addresses eleven disclosed CVEs, and updates numerous dependencies.
Action needed (2)
securityhighEleven disclosed CVEs, fixed
The release fixes eleven disclosed CVEs: CVE-2026-42501, CVE-2026-42499, CVE-2026-39836, CVE-2026-39826, CVE-2026-39825, CVE-2026-39823, CVE-2026-39820, CVE-2026-39819, CVE-2026-39817, CVE-2026-33814, and CVE-2026-33811.
breakingThe
config.default, changedlinkerd. io/proxy-enable-native-sidecar The default sidecar mode changes through
config., making native sidecars the default.linkerd. io/proxy-enable-native-sidecar
A maintenance release with operator-visible bug fixes, narrower EndpointSlice watch behavior, new Helm configurability, and dependency and image updates. It also includes a security-related dependency update without a disclosed advisory identifier.
Action needed (2)
securityThe
github.dependency updatecom/moby/spdystream The security-related
github.dependency is updated to v0.5.1.com/moby/spdystream breakingService-label filtering for
EndpointSlicewatchesThe
loadbalancer/reflectorscomponent now filtersEndpointSlicewatches by service labels.
Check if affected (1)
breakingService-label filtering for
EndpointSlicesApplies if
--k8s-service-proxy-nameis set.
A maintenance release with an enforced policy behavior change, bug fixes, new metrics, and Helm image overrides. It also updates dependencies and container images and refreshes container image manifests.
Action needed (1)
securityThe
github.dependency updatecom/moby/spdystream The
github.module is updated tocom/moby/spdystream v0.in v1.17.16.5. 1
Check if affected (1)
breaking
CiliumLocalRedirectPolicyaddressMatcheroverride behaviorApplies if you use
addressMatcherinCiliumLocalRedirectPolicyand do not enable--enable-lrp-address-matcher-override=true.
Cilium v1.18.10 contains correctness fixes, Helm support for overriding images, and dependency and image updates. The github. update is marked as a security update, but no advisory identifier is provided.
Action needed (1)
securityThe
github.module update to v0.5.1com/moby/spdystream Cilium v1.18.10 updates the
github.module to v0.5.1 as an undisclosed security update.com/moby/spdystream
This release narrows Kubernetes support to version 1.31 or newer. It also adds multicluster gateway configuration, reduces destination-controller memory usage, corrects namespace-aware service cleanup, and updates third-party dependencies.
Check if affected (1)
breakingMinimum supported
Kubernetesversion, 1.31Applies when your cluster runs
Kubernetesolder than1..31