A release with security corrections, breaking configuration removals, and an output-field rename that may require operator or log-collector changes. It also adds TLS and cache configuration, query and tracing changes, and defect fixes across several Thanos components.
Action needed (1)
securitycritical
thanos-community/grpc-gofork update for CVE-2026-33186The
thanos-community/grpc-gofork is bumped to fix CVE-2026-33186, an authorization bypass via malformed:pathheaders.
Check if affected (4)
security
Receivetenant ID validationApplies if you run
Receive.Receivevalidates tenant IDs extracted from split-tenant labels to prevent path traversal.breaking
Query-Frontendtime_takenfield renamed totime_taken_msApplies if you run
Query-Frontend.The
Query-FrontendJSON output now usestime_taken_msinstead oftime_taken, for consistent output and easier parsing by log collectors.breaking
--shipper.flag removedignore-unequal-block-size Applies if you configure
--shipper..ignore-unequal-block-size The breaking
--shipper.flag is removed fromignore-unequal-block-size Receive.- + 1 more on the release page