This release adds attestors, plugins, configuration options, and CLI/API capabilities. It also updates dependencies and includes behavior changes and defect fixes, with no security advisories or explicitly described vulnerabilities.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A substantial operator-facing release with new CLI, Helm, and policy capabilities alongside fixes and dependency updates. It also changes existing behavior through security fixes, deprecations, removals, and stricter constraints that may require review before upgrading.
Action needed (7)
securityhighIntermediate certificate limits
Intermediate certificates are limited to mitigate CVE-2026-32280. The fix ships in Kyverno v1.19.0.
securityhighGo toolchain 1.26.3
The Go toolchain was upgraded to 1.26.3 to resolve CVE-2026-39836. The updated toolchain ships in Kyverno v1.19.0.
securityRegenerated CRDs and documentation for GHSA-79gf-7frw-68m9
CRDs and documentation were regenerated after the API bump associated with GHSA-79gf-7frw-68m9. The updated artifacts ship in Kyverno v1.19.0.
securityUpdated
golang.andorg/x/crypto x/netdependenciesThe
golang.dependency was updated to v0.53.0 andorg/x/crypto x/netto v0.56.0 to resolve security CVEs. The dependency updates ship in Kyverno v1.19.0.securityPatched ORAS and sigstore vulnerabilities
The ORAS and sigstore dependencies were patched for CodeQL vulnerabilities. The dependency fixes ship in Kyverno v1.19.0.
securityCodeQL vulnerability fixes
Open CodeQL security vulnerabilities were addressed. The fixes ship in Kyverno v1.19.0.
security
cel-gov0.30.0cel-gowas updated to v0.30.0 to resolve CVE-2026-GHSA-gcjh-h69q-9w9g. The updated dependency ships in Kyverno v1.19.0.
Check if affected (6)
breakingRequired
--resourcefor the migrate commandApplies when the migrate command runs.
breakingDefault
userInfogroups and UID during background scansApplies when background scans run.
breaking
excludeBootstrapResourceswebhook flagApplies when you configure Fail webhooks.
- + 3 more on the release page
Plan ahead (1)
deprecatedDeprecation notices for legacy
kyverno.policy typesio Applies when you use legacy
kyverno.policy types.io
A maintenance release with disclosed security fixes, a cleartext vault-keystore password correction, a Quarkus dependency upgrade, and other bug corrections. The fixes cover account and permission flows, secret handling, and runtime dependencies.
Action needed (2)
securitymediumCVE-2026-59888 and CVE-2026-59889 fixes in
jackson-databindjackson-databindis upgraded to 2.21.5 to address CVE-2026-59888 and CVE-2026-59889. The dependency update ships in this Keycloak release.securitymediumCVE-2026-45292 OpenTelemetry Java SDK memory allocation correction
CVE-2026-45292 corrects unbounded memory allocation in W3C Baggage Propagation in the OpenTelemetry Java SDK.
Check if affected (6)
securitycriticalCVE-2026-18963 reset-credentials flow bypass correction
Applies if you use the
reset-credentials flow.securityhighCVE-2026-15571 predictable account-linking hash correction
Applies if you use
oidc.securitymediumCVE-2026-14613 fine-grained admin permissions bypass correction
Applies if you use the
admin/fine-grained-permissionsAPI.- + 3 more on the release page
A security-focused maintenance release updates the Go build dependency to 1. and addresses standard-library vulnerabilities used by OPA's HTTP handler and crypto builtins. Operators building their own binaries or images control the Go version used in those builds.
Action needed (1)
securitycritical
Go1.build dependency26. 6 OPA is built with
Go1., fixing standard-library vulnerabilities in code used by its HTTP handler and crypto builtins. The fixes address26. 6 GO-2026-5026,GO-2026-5972,GO-2026-6088,GO-2026-6089,GO-2026-6090,GO-2026-6091, andGO-2026-6218.
A corrective and performance-focused release with operator-visible default and constraint changes, deprecated flag removal, and dependency vulnerability fixes. It also expands scanning, output, registry, and MCP capabilities.
Action needed (3)
securityBatch dependency vulnerability fixes
Batch 1 and 2 dependency vulnerability fixes are included in this release.
breakingRegoV1 evaluation and v0 compatibility shim removal
Rego evaluation now uses RegoV1 and drops the v0 compatibility shim in this release.
breakingLoopback-only constraint
A loopback-only constraint is applied in this release.
Check if affected (3)
breakingOpt-in
pprof debug serverApplies if you enable the
pprof debug server.breaking
--frameworksdefault set to allApplies if you do not configure
--frameworks.breakingDeprecated flags removal
Applies if you configure
deprecated flags.
OpenFGA v1.18.3 includes a correctness fix for an experimental graph check. No operator-facing change details are included in the recorded release items.
Source ↗A maintenance release with security fixes and additional bug fixes. The security fixes require upgrading, and the ordinary bug fixes require no operator action beyond upgrading.
Check if affected (12)
securityhighCVE-2026-15573 unnormalized URI matching in
pathmatcherApplies if you use
pathmatcher.securityhighCVE-2026-15572 DCR protocol mapper type-swap policy
Applies if you use DCR.
securityhighCVE-2026-16442 SAML broker login restriction
Applies if you use the SAML broker.
- + 9 more on the release page
A maintenance release with diagnostic logging, experimental cache metric changes, and corrections for weighted-graph and tuple-validation defects. It also updates the Go toolchain and embedded grpc-health-probe in released images.
Action needed (1)
securityhigh
grpc-health-proberebuilt atv0.4. 53 The embedded
grpc-health-probeis rebuilt with Go 1.26.5 and bumped tov0.in released images. The update addresses the Go standard library vulnerabilities documented in the Go 1.26.5 release notes, including CVE-2026-39822.4. 53