RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

May 2026Clear ×
Ciliumv1.18.10Networking & MessagingMay 13, 2026

Cilium v1.18.10 contains correctness fixes, Helm support for overriding images, and dependency and image updates. The github.com/moby/spdystream update is marked as a security update, but no advisory identifier is provided.

Action needed (1)

  • securityThe github.com/moby/spdystream module update to v0.5.1

    Cilium v1.18.10 updates the github.com/moby/spdystream module to v0.5.1 as an undisclosed security update.

Source
Argov3.3.10CI/CD & App DeliveryMay 12, 2026

This release combines bug fixes with dependency and toolchain updates. The Go update to 1.25.9 addresses CVEs and concerns deployments using this release.

Action needed (1)

  • securityThe Go toolchain, updated to 1.25.9

    The Go toolchain is updated to 1.25.9 on release-3.3 to resolve CVEs.

Source
Fluxv2.8.7CI/CD & App DeliveryMay 12, 2026

Flux v2.8.7 includes a security update to the go-git dependency alongside toolkit component updates. The go-git update addresses CVE-2026-45022 and GHSA-389r-gv7p-r3rp.

Action needed (1)

  • securityhighThe go-git dependency update to v5.19.0

    The go-git dependency is updated to v5.19.0, which fixes CVE-2026-45022 and addresses GHSA-389r-gv7p-r3rp. This update ships in Flux v2.8.7.

Source
Open Policy Agent (OPA)v1.16.2SecurityMay 12, 2026

OPA v1.16.2 is a security-focused maintenance release. It updates the Go version used to build OPA binaries and images to 1.26.3 to address vulnerabilities.

Action needed (1)

  • securityThe Go build version, updated to 1.26.3

    The version of Go used to build OPA binaries and images is updated to 1.26.3 to address vulnerabilities.

Source
Flatcar Container Linuxstable-4593.2.1Provisioning & RuntimeMay 11, 2026

This is a security-focused Flatcar release with disclosed Linux security fixes. It also updates the Linux and ca-certificates dependencies.

Action needed (1)

  • securitycriticalLinux security updates, including CVE-2026-31733

    Linux receives security updates in Flatcar stable-4593.2.1, including CVE-2026-31733 and the other disclosed Linux advisories listed for this change.

Source
Volcanov1.12.4Orchestration & ManagementMay 9, 2026

A maintenance release with a security fix for a disclosed denial-of-service vulnerability in the webhook server, plus ordinary scheduling bug fixes. The vulnerability affects webhook servers that accept unbounded HTTP request bodies.

Check if affected (1)

  • securitymediumCVE-2026-44247 in the Volcano webhook server

    Applies if the Volcano webhook server runs.

Source
Volcanov1.13.3Orchestration & ManagementMay 9, 2026

Volcano v1.13.3 includes a security fix for a denial-of-service vulnerability in the webhook server. It also contains other defect corrections.

Check if affected (1)

  • securitymediumCVE-2026-44247 in the Volcano webhook server

    Applies if a pod can access the Volcano webhook endpoint over the network.

Source
Volcanov1.14.2Orchestration & ManagementMay 9, 2026

A maintenance release fixes a disclosed webhook denial-of-service vulnerability and corrects scheduler, queue, and event-handling defects. It also updates the Kubernetes version used by the webhook-manager image.

Check if affected (1)

  • securitymediumCVE-2026-44247: Webhook server request body handling

    Applies if the Volcano webhook server runs.

Source
Harborv2.15.1Storage & DataMay 6, 2026

Harbor v2.15.1 is a maintenance release with defect corrections, behavior changes, and dependency and base-image updates. It also updates photon packages to fix CVEs.

Action needed (1)

  • securityphoton packages CVE fixes

    The photon packages are updated to fix CVEs in Harbor v2.15.1.

Source
Argov3.4.1CI/CD & App DeliveryMay 6, 2026

A broad maintenance and feature release with correctness, performance, dependency, and operator-facing changes. Operators should review the cluster-version annotation format and changed defaults, while dependency updates include Kubernetes and Helm changes; no explicitly disclosed exploitable vulnerability or security advisory is identified.

Action needed (4)

  • securityThe k8s.io/kubernetes module, updated to v1.34.2

    The k8s.io/kubernetes module is updated to v1.34.2 as a security-related dependency update.

  • securityThe helm dependency, updated to 3.19.4

    The helm dependency is updated to 3.19.4 due to a CVE.

  • breakinggRPC service config DNS TXT lookups, disabled by default

    gRPC service config DNS TXT lookups are disabled by default.

  • breakingThe appset resource status count, defaulted to 5000

    The default appset resource status count is changed to 5000.

Check if affected (2)

  • breakingThe --client flag in the Helm version command, removed

    Applies if you use --client.

  • breakingThe cluster-version annotation format, renamed

    Applies if you use Application Sets with Cluster Generators and configure argocd.argoproj.io/auto-label-cluster-info.

Source
CRI-Ov1.36.0Kubernetes CoreMay 5, 2026

CRI-O v1.36.0 is a substantive operator-facing feature and maintenance release with runtime and operational changes. It also includes a security update to spdystream and a broad dependency refresh.

Action needed (1)

  • securityhighThe spdystream dependency update for CVE-2026-35469

    CRI-O v1.36.0 updates the spdystream dependency to fix CVE-2026-35469.

Source
Confidential Containersv0.20.0SecurityMay 5, 2026

Confidential Containers v0.20.0 combines operator-visible capability and compatibility updates with deprecations of several image and provider paths. It also includes a security fix identified by GHSA-q49m-57vm-c8cc.

Action needed (1)

  • securityhighGHSA-q49m-57vm-c8cc security fix

    The release includes a fix for the security issue identified by GHSA-q49m-57vm-c8cc.

Plan ahead (3)

  • deprecatedThe Docker CAA provider, deprecatedremoval date not announced

    Applies if you use the Docker CAA provider.

  • breakingThe Fedora-based mkosi CAA podvm image, deprecatedremoval date not announced

    Applies if you use the Fedora-based mkosi CAA podvm image.

  • deprecatedSupport for packer images, deprecatedremoval date not announced

    Applies if you use packer images.

Source
CRI-Ov1.35.3Kubernetes CoreMay 5, 2026

A maintenance release that adds a runtime metric and a GOMAXPROCS configuration field, fixes two runtime defects, and reverts CNI monitoring after node bootstrapping regressions. It also updates the spdystream dependency to address CVE-2026-35469.

Action needed (2)

  • securityhighThe spdystream dependency update for CVE-2026-35469

    The spdystream dependency is updated to address CVE-2026-35469. The update ships in this release.

  • breakingCRI-O CNI monitoring, reverted

    CRI-O reverts CNI monitoring because it caused node bootstrapping regressions. The change ships in this release.

Source
CRI-Ov1.34.8Kubernetes CoreMay 5, 2026

CRI-O v1.34.8 includes a security-relevant dependency update and adds operator-facing observability and configuration capabilities. The dependency update is the release change that requires upgrading, while the other additions concern optional setup or informational use.

Action needed (1)

  • securityhighCVE-2026-35469 fix in the spdystream dependency

    CRI-O v1.34.8 updates the spdystream dependency to fix CVE-2026-35469.

Source
CRI-Ov1.33.12Kubernetes CoreMay 5, 2026

CRI-O v1.33.12 includes a security fix for a disclosed vulnerability in the spdystream dependency. It also adds the min_injected_gomaxprocs configuration field for controlling the floor of injected GOMAXPROCS values.

Action needed (1)

  • securityhighCVE-2026-35469 fix in the spdystream dependency

    CVE-2026-35469 is fixed by updating the spdystream dependency in CRI-O v1.33.12.

Source
etcdv3.6.11Kubernetes CoreMay 1, 2026

A maintenance release with a correctness fix, an RBAC authorization bypass fix, and a security-related dependency update for GO-2026-4962. It also records Go 1.25.9 as the toolchain used to build the binaries.

Action needed (1)

  • securitymediumgolang.org/x/image update for GO-2026-4962

    The release updates golang.org/x/image to v0.39.0 to resolve GO-2026-4962.

Check if affected (1)

  • securityRBAC authorization bypass in nested Put requests

    Applies if you use RBAC.

Source
etcdv3.5.30Kubernetes CoreMay 1, 2026

A maintenance release with a security fix for an RBAC authorization bypass in transaction handling. It also includes an ordinary correctness fix and a Go toolchain dependency update.

Action needed (1)

  • securityRBAC authorization bypass in nested etcd transactions

    The release fixes an RBAC authorization bypass that allowed read access through PrevKv or lease attachment in Put requests nested in etcd transactions. The fix ships in this release.

Source
etcdv3.4.44Kubernetes CoreMay 1, 2026

A security maintenance release fixes an RBAC authorization bypass. It also updates the Go toolchain used to compile binaries to go 1.25.9.

Check if affected (1)

  • securityRBAC authorization bypass fix

    Applies if you use RBAC.

Source
← Newer
Browse by month