A maintenance release with a correctness fix, an RBAC authorization bypass fix, and a security-related dependency update for GO-2026-4962. It also records Go 1. as the toolchain used to build the binaries.
Action needed (1)
securitymedium
golang.update fororg/x/image GO-2026-4962The release updates
golang.toorg/x/image v0.to resolve39. 0 GO-2026-4962.
Check if affected (1)
securityRBAC authorization bypass in nested
PutrequestsApplies if you use
RBAC.The release fixes an RBAC authorization bypass that could allow read access through
PrevKvor lease attachment inPutrequests nested in etcd transactions.