RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jan 2026Clear ×
OpenFGAv1.11.3SecurityJan 28, 2026

This release adds configuration and observability capabilities while changing throttling and metric behavior. It also fixes correctness defects, including a described improper policy enforcement issue.

Action needed (2)

  • securitymediumThe CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9 policy enforcement fix

    The release fixes improper policy enforcement associated with CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9.

  • breakingThe custom grpc_code metric label, removed

    The custom grpc_prometheus fork is replaced with go-grpc-middleware's provider, and the custom grpc_code label is removed from the metric.

Source
Kyvernov1.15.3SecurityJan 27, 2026

A maintenance release with security-related fixes for the Go toolchain and cross-namespace access through apiCall. It also contains ordinary defect fixes and capability or behavior changes.

Action needed (1)

  • securityThe go version update for standard library CVEs

    The go version is updated to fix standard library CVEs in this release.

Check if affected (1)

  • securityCross-namespace access through apiCall prevented

    Applies if you use apiCall.

Source
Keycloak26.5.2SecurityJan 23, 2026

Keycloak 26.5.2 is a maintenance release with security fixes alongside ordinary bug fixes and enhancements. The security updates affect third-party dependencies and Keycloak's token issuance logic.

Action needed (3)

  • securitymediumCVE-2025-67735 in netty-codec-http

    CVE-2025-67735 addresses request smuggling via CRLF injection in netty-codec-http. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-66560 in io.quarkus/quarkus-rest

    CVE-2025-66560 addresses the Quarkus REST worker thread exhaustion vulnerability in io.quarkus/quarkus-rest. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-14559 in keycloak-services

    CVE-2025-14559 addresses a business logic flaw in keycloak-services that allowed unauthorized token issuance for disabled users. The fix ships in Keycloak 26.5.2.

Source
Keycloak26.5.1SecurityJan 14, 2026

Keycloak 26.5.1 is a maintenance release with a security fix in the Organization feature. It also contains correctness fixes, a performance improvement, and changes to HTTP responses and realm administration.

Check if affected (1)

  • securityThe Organization feature account-name exposure fix

    Applies if you use the Organization feature.

Source
Keycloak26.5.0SecurityJan 6, 2026

A substantial feature and maintenance release adds operator capabilities including workflows, JWT authorization grants, organization invitations, OpenTelemetry export, and Windows services. It also updates Quarkus and fixes correctness issues, while changing supported database versions and addressing a vulnerability in brute force detection settings.

Check if affected (2)

  • securityBrute force detection settings vulnerability, corrected

    Applies if you configure brute force detection settings.

  • breakingPostgreSQL 13.x support removal

    Applies if you depend on PostgreSQL 13.x.

Plan ahead (1)

  • deprecatedFine-Grained Admin Permissions v1, deprecated

    Applies if you enable admin/fine-grained-permissions.

Source
Browse by month