A release with fixes for two disclosed security vulnerabilities, updated Kubernetes and Kafka support, and a changed feature-gate default. It also adds Kafka 4.2.0 support and per-listener Kafka options, while the ingress listener type is deprecated; CRD upgrades and a KafkaUser field migration are upgrade prerequisites.
Action needed (2)
securityhighCVE-2026-27133 and CVE-2026-27134 security fixes
Security fixes in Strimzi 0.50.1 and 0.51.0 address CVE-2026-27133 and CVE-2026-27134, with advisories GHSA-2qwx-rq6j-8r6j and GHSA-6x85-j2f7-4xc5.
breakingThe
ServerSideApplyPhase1feature gate defaultThe
ServerSideApplyPhase1feature gate moved to beta and is enabled by default.
Check if affected (2)
breaking
Kubernetesversion supportApplies if you use
Kubernetes1.27, 1.28, or 1.29.breaking
Kafka4.0.0 and 4.0.1 supportApplies if you use
Kafka4.0.0 or 4.0.1.
Plan ahead (1)
deprecatedThe
ingresslistener type deprecationApplies if you configure the
ingresslistener type.