RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Sep 2026Clear ×
cert-managerv1.20.4SecurityTodaySep 16, 2026

A security-focused patch release fixes multiple dependency vulnerabilities and an ingress-shim defect. It also updates distroless base images and release-signing procedures.

Action needed (6)

  • securityhighThe golang.org/x/net, golang.org/x/text, and golang.org/x/crypto versions

    golang.org/x/net is updated to v0.58.0, golang.org/x/text to v0.41.0, and golang.org/x/crypto to v0.55.0. The updates fix CVE-2026-46600, CVE-2026-56852, and CVE-2026-56854.

  • securityhighThe google.golang.org/grpc version and advisory fixes

    google.golang.org/grpc is updated to v1.83.2 to fix CVE-2026-84304, CVE-2026-84445, CVE-2026-84303, GHSA-vp52-pcj8-j9qc, GHSA-2v4p-qf9q-27wj, and GHSA-hrxh-6v49-42gf.

  • securityThe Go version and standard library security fixes

    Go is updated to 1.26.5 and then 1.26.6. These versions include security fixes for the go command and the crypto/tls, encoding/asn1, encoding/xml, html/template, net, net/http, and net/url packages.

  • securitymediumThe github.com/google/cel-go version

    github.com/google/cel-go is updated to v0.30.0 to fix the reported vulnerability GHSA-gcjh-h69q-9w9g.

  • securityThe security-scanned Go dependencies

    golang.org/x/mod, go.opentelemetry.io/otel, and go.etcd.io/etcd/client/pkg/v3 are updated to versions flagged by security scanners.

  • securitymediumThe software.sslmate.com/src/go-pkcs12 version

    software.sslmate.com/src/go-pkcs12 is updated to v0.7.2 to fix the reported vulnerability GHSA-mpwr-8vm7-h73f.

Source
Keycloak26.7.4SecurityTodaySep 16, 2026

A security-heavy maintenance release with vulnerability fixes, alongside correctness and performance corrections. It also updates the Quarkus dependency.

Action needed (4)

  • securityhighCVE-2026-79651 and unbounded locale caching

    CVE-2026-79651 fixes an unauthenticated denial-of-service issue caused by unbounded locale caching. The fix ships in this release.

  • securityhighCVE-2026-74909 and matrix parameter stripping

    CVE-2026-74909 completes the fix for a percent-encoded semicolon bypass of matrix parameter stripping in PathMatcher. The fix ships in this release.

  • securityhighCVE-2026-17526 and the impersonation role

    CVE-2026-17526 fixes privilege escalation involving the impersonation role impersonating a realm administrator. The fix ships in this release.

  • securitymediumCVE-2026-19607 and username takeover

    CVE-2026-19607 fixes a username takeover issue that could lead to account lockout. The fix ships in this release.

Check if affected (2)

  • securityhighCVE-2026-18212 and SAML Redirect DEFLATE helpers

    Applies if you use SAML Redirect.

  • securityCVE-2026-90997 and stateless replay gate row counts

    Applies if you use MySQL/MariaDB.

Source
Ciliumv1.18.14Networking & MessagingTodaySep 16, 2026

A maintenance release focused on bug fixes, dependency updates, and image refreshes. It also removes a datapath behavior and includes security dependency fixes that may require operator attention.

Action needed (3)

  • securityThe google.golang.org/grpc module, updated to v1.83.1

    The google.golang.org/grpc module is updated to v1.83.1 in this release as a security dependency fix.

  • securityThe google.golang.org/grpc module, updated to v1.83.2

    The google.golang.org/grpc module is updated to v1.83.2 in this release as a security dependency fix.

  • breakingThe Ingress HostFW Policy between RevSNAT and RevDNAT, removed

    The Ingress HostFW Policy between RevSNAT and RevDNAT is removed in this release.

Source
Crossplanev2.4.1Orchestration & ManagementYesterdaySep 15, 2026

A maintenance release with a package-revision handoff fix and dependency security updates. It includes the gRPC advisory GHSA-2v4p-qf9q-27wj and refreshes the Go toolchain and related dependencies.

Action needed (3)

  • securityhighgoogle.golang.org/grpc update for GHSA-2v4p-qf9q-27wj

    google.golang.org/grpc is updated to v1.83.2 to pick up upstream fixes, including advisory GHSA-2v4p-qf9q-27wj. The update ships with the release's dependency security refresh.

  • securityThe Go toolchain update

    The Go toolchain is updated to 1.26.7 as part of the dependency security updates. The release also updates google.golang.org/grpc to v1.83.2, golang.org/x/crypto to v0.56.0, github.com/crossplane/crossplane/apis/v2 to v2.4.0, and refreshes the lock file.

  • securitygolang.org/x/crypto update

    golang.org/x/crypto is updated to v0.56.0 as part of the dependency security updates. The same refresh updates the Go toolchain to 1.26.7, google.golang.org/grpc to v1.83.2, and refreshes the lock file.

Source
Crossplanev2.3.6Orchestration & ManagementYesterdaySep 15, 2026

A maintenance release fixes package-revision handoff failures and updates security-sensitive dependencies. It adds no newly announced operator configuration requirements.

Action needed (2)

  • securityThe golang.org/x/crypto dependency update

    The golang.org/x/crypto module is updated to v0.56.0 for a security-related dependency change.

  • securityThe google.golang.org/grpc dependency update

    The google.golang.org/grpc module is updated to v1.83.2 for a security-related dependency change.

Source
Crossplanev2.2.6Orchestration & ManagementYesterdaySep 15, 2026

A security-focused maintenance release with updates to the Go toolchain and dependencies for upstream CV fixes. Package-revision handoffs are also corrected so incoming revisions can take control of established objects without manual intervention.

Action needed (3)

  • securityhighThe google.golang.org/grpc update for GHSA-2v4p-qf9q-27wj

    google.golang.org/grpc is updated to v1.83.2 to pick up upstream CVE fixes, including advisory GHSA-2v4p-qf9q-27wj. The updated dependency ships in this release.

  • securityThe Go toolchain security update

    The Go toolchain is updated to 1.26.7 to pick up upstream CVE fixes. The lock file is also refreshed.

  • securityThe golang.org/x/crypto security update

    golang.org/x/crypto is updated to v0.56.0 to pick up upstream CVE fixes. The updated dependency ships in this release.

Source
Crossplanev1.20.13Orchestration & ManagementYesterdaySep 15, 2026

A security-focused maintenance release updates the Go toolchain and dependencies. It includes upstream vulnerability fixes, including a disclosed gRPC advisory.

Action needed (2)

  • securityhighgoogle.golang.org/grpc update and GHSA-2v4p-qf9q-27wj fixes

    The release updates google.golang.org/grpc to v1.83.2 and includes a combined set of vulnerable dependency updates for upstream CVE fixes. This includes the gRPC advisory GHSA-2v4p-qf9q-27wj.

  • securityGo toolchain update to 1.26.7

    The release bumps the Go toolchain to 1.26.7.

Source
Backstagev1.55.0CI/CD & App DeliveryYesterdaySep 15, 2026

A broad feature and maintenance release adds scaffolder recovery and credential controls, TechDocs, notification and streaming capabilities, and Kubernetes and authentication improvements. It also includes dependency and tooling security updates, a security fix, and compatibility changes that affect users of the listed resolvers, catalog integrations, MCP configuration, and task recovery.

Action needed (6)

  • securityModule Federation dependency updates for security

    This release updates the Module Federation dependencies to versions that avoid known security vulnerabilities.

  • securityYarn tooling dependency updates for security

    This release updates the Yarn tooling dependencies to versions that avoid known security vulnerabilities.

  • securityModule Federation security dependency update

    This release updates the Module Federation dependencies to versions that avoid known security vulnerabilities.

  • securityOpenAPI generator tooling security update

    This release updates the OpenAPI generator tooling to avoid known security vulnerabilities.

  • securityOpenAPI generator tooling security update

    This release updates the OpenAPI generator tooling to avoid known security vulnerabilities.

  • breakingLocale-insensitive Unicode casing

    String handling now uses locale-insensitive Unicode casing for consistent results across environments.

Check if affected (6)

  • securityKubernetes catalog cluster locator URL validation

    Applies if you use the catalog cluster locator.

  • securityPull request workspace handling security fix

    Applies if you use pull request workspace handling.

  • breakingGitHub user ID catalog lookup matching

    Applies if you use GitHub user ID catalog lookups.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedGitHub username sign-in resolver deprecation

    Applies if you use the GitHub username sign-in resolver.

Source
CRI-Ov1.37.0Kubernetes CoreYesterdaySep 15, 2026

A substantial feature and compatibility release for operators, with changed defaults and interfaces alongside correctness and performance improvements. It also includes identified security fixes and refreshes a broad set of dependencies.

Action needed (2)

  • securityhighThe CVE-2026-15809 /etc/passwd injection fix

    CRI-O fixes CVE-2026-15809, which allowed a bypass of the CVE-2022-4318 fix and /etc/passwd injection through newline characters in the HOME environment variable.

  • securityhighThe Go toolchain, updated to 1.26.4

    The Go toolchain is updated to 1.26.4 to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507.

Check if affected (4)

  • breakingThe insecure_registries option and --insecure-registry flag, removed

    Applies if you configure insecure_registries or use --insecure-registry.

  • breakingThe container_level_enabled default, changed to checkpoint_only

    Applies if you do not configure container_level_enabled.

  • breakingThe gRPC message size defaults, reduced to 16 MiB

    Applies if grpc_max_send_msg_size or grpc_max_recv_msg_size is not configured.

  • + 1 more on the release page
Source
Flatcar Container Linuxstable-4757.2.0Provisioning & RuntimeSep 14, 2026

A security-focused maintenance release with extensive Linux and OpenSSH vulnerability remediation, broad dependency updates, and platform and image changes. Operators should account for the dropped platform and image support and the new Vagrant 2.2.5 requirement.

Action needed (41)

Source
cert-managerv1.21.2SecuritySep 11, 2026

A maintenance release focused on correctness and data-exposure fixes. It also includes security-related dependency updates and a stricter default for namespaced Vault authentication.

Action needed (6)

  • securityACME server response body limit

    ACME server response bodies are capped at 16 MiB to prevent unbounded-body denial-of-service conditions.

  • securityChallenge.status.reason response disclosure fix

    The ACME HTTP-01 self-check no longer copies the fetched response body into Challenge.status.reason. This prevents internal response contents reached through redirects from being disclosed.

  • securityGo 1.26.6

    The release upgrades Go to 1.26.6, which includes security fixes in the Go command and several standard library packages.

  • securitygoogle.golang.org/grpc v1.83.2

    The release updates google.golang.org/grpc to v1.83.2 to fix reported security vulnerabilities.

  • securitygolang.org/x/crypto v0.56.0

    The release updates golang.org/x/crypto to v0.56.0 to fix reported security vulnerabilities.

  • breakingValidation for converted AdmissionReview requests

    Validation now also applies to equivalent-converted AdmissionReview requests on non-v1 API versions. These requests could previously bypass validation.

Check if affected (1)

  • breakingNamespaced Vault issuer ambient credentials default

    Applies if you use a namespaced Issuer with Vault AWS IAM authentication.

Source
OpenFeaturecore/v0.17.0CI/CD & App DeliverySep 10, 2026

A feature-oriented release expands FIPS, HTTP, and SSE support and makes file polling configurable. It also includes a security-related update to the gRPC dependency.

Action needed (1)

  • securityThe google.golang.org/grpc dependency, updated to v1.83.1

    The google.golang.org/grpc module is updated to v1.83.1 in the core release.

Source
OpenFeatureflagd-proxy/v0.9.9CI/CD & App DeliverySep 10, 2026

A security-focused maintenance release updates gRPC and resolves dependency alerts. It also adds an additional FIPS 140-3 mode.

Action needed (2)

  • securityThe google.golang.org/grpc module, updated to v1.83.1

    The google.golang.org/grpc module is updated to v1.83.1 in this release.

  • securityDependabot security alerts resolved

    Open Dependabot security alerts are resolved in this release.

Source
OpenFeatureflagd/v0.16.3CI/CD & App DeliverySep 10, 2026

A feature-focused release adds FIPS 140-3, HTTP and SSE capabilities, and changes OFREP ETag behavior. It also updates gRPC for an undisclosed security fix.

Action needed (1)

  • securityThe google.golang.org/grpc module update

    The google.golang.org/grpc module is updated to v1.83.1 for an undisclosed security fix.

Source
Kyvernov1.19.1SecuritySep 10, 2026

A security-focused maintenance release with dependency updates and fixes for policy and egress behavior. It also includes correctness changes, deprecation warning enforcement, and a narrowed policy constraint that may require operator changes.

Action needed (2)

  • securitycriticalGo and x/net updates for CVE-2026-39821

    The release updates Go to 1.26.6 and x/net to resolve CVE-2026-39821.

  • securityhighGo update for CVE-2026-56853

    The release updates Go to address CVE-2026-56853.

Check if affected (3)

  • securityPolicyException scope bypass fix for GHSA-5cjf-wwfg-pj4c

    Applies if you use the PolicyException CRD.

  • securityapiCall.service egress blocklist bypass fix

    Applies if you configure apiCall.service egress.

  • breakingglobalContext constraint in namespaced policies

    Applies if you use globalContext in namespaced policies.

Source
Helmv4.3.0Kubernetes CoreSep 9, 2026

A feature release adding new Helm capabilities and output options, alongside correctness fixes and performance improvements. It also includes dependency updates with two disclosed security-related bumps.

Action needed (3)

  • securitycriticalgolang.org/x/net update for GO-2026-5026

    Helm updates golang.org/x/net to v0.55.0 to address GO-2026-5026.

  • securitymediumgo.opentelemetry.io/otel update for GO-2026-5158

    Helm updates go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158.

  • breakingPer-file decompression size limit removal

    Helm removes the per-file decompression size limit from file decompression.

Check if affected (1)

  • breakingOwnership verification before resource deletion

    Applicability is not stated in the release notes.

Source
OpenFGAv1.20.0SecuritySep 8, 2026

A maintenance release updates the Go toolchain and images to address a security advisory. It also fixes a ListUsers deadlock that could cause timeouts with partial results.

Action needed (1)

  • securitycriticalGo toolchain and images at go1.26.8

    The Go toolchain and images are upgraded to use go1.26.8, addressing CVE-2026-39821 and Go advisory GO-2026-5026.

Source
Prometheusv3.13.3ObservabilitySep 7, 2026

A maintenance release with security-related dependency updates and correctness fixes across shutdown handling, query matching, service discovery, and TSDB reliability. No configuration or default changes are stated.

Action needed (1)

  • securityhighSecurity updates for github.com/klauspost/compress and golang.org/x/crypto

    The release updates github.com/klauspost/compress to v1.18.7 for GO-2026-5841 and golang.org/x/crypto to v0.55.0 for GO-2026-6303.

Source
Contourv1.33.7Networking & MessagingSep 7, 2026

A security maintenance release updates Envoy, Go, and other dependencies to address CVEs. It is tested against Kubernetes 1.32 through 1.34, with no stated operator configuration changes.

Action needed (3)

  • securityThe Envoy version, updated to v1.38.4

    Envoy is updated to v1.38.4 to address CVEs. The update ships in this release.

  • securityThe Go version, updated to 1.26.8

    Go is updated to 1.26.8 to address CVEs. The update ships in this release.

  • securityDependency updates for CVE fixes

    Dependencies are updated to address CVEs. The dependency updates ship in this release.

Source
containerdv1.7.35Kubernetes CoreSep 4, 2026

A security-focused maintenance release with fixes for vulnerabilities and changes to image fetching and Windows log handling. Runtime and performance improvements are also included.

Action needed (2)

Check if affected (1)

  • breakingThe ScrubLogs default on Windows

    Applies if you run on Windows.

Source
containerdv2.0.12Kubernetes CoreSep 4, 2026

A security-focused maintenance release fixes two disclosed vulnerabilities, changes the Windows logging default, and hardens registry fetching. It also includes correctness and performance fixes.

Action needed (2)

  • securityCVE-2026-53495 and GHSA-7jxh-36q5-gcqv security fix

    This release fixes the disclosed vulnerability identified by CVE-2026-53495 and GHSA-7jxh-36q5-gcqv.

  • securityGHSA-rp3h-jf77-q9p4 security fix

    This release fixes the disclosed vulnerability identified by GHSA-rp3h-jf77-q9p4.

Check if affected (1)

  • breakingThe ScrubLogs Windows default

    Applies if you run containerd on Windows.

Source
containerdv2.2.8Kubernetes CoreSep 4, 2026

A security and maintenance release with fixes for two security advisories, request hardening, runtime and snapshot correctness, and a small performance improvement. No operator migration requirement is stated.

Action needed (2)

Source
Kubescapev4.0.13SecuritySep 2, 2026

A broad feature release expands scanning, policy, reporting, remediation, notifications, telemetry, integrations, and output capabilities. It also includes security hardening and stricter scan constraints, alongside many correctness and runtime fixes.

Action needed (2)

  • securityGo dependency security vulnerabilities

    Dependabot fixes security vulnerabilities in Go dependencies shipped with the release.

  • securitygosec SAST findings

    The release remediates gosec SAST findings in the Go codebase.

Check if affected (10)

  • securityGrafeas filtering through resourceURL

    Applies if you run imagescan.

  • breakingClient-supplied account and accessKey in scan requests

    Applies if you use scan requests.

  • breakingHard validation for --include-controls

    Applies if you configure --include-controls.

  • + 7 more on the release page

Plan ahead (1)

  • deprecatedThe --fail-threshold flag, hidden and deprecated

    Applies if you configure --fail-threshold.

Source
Browse by month