A security maintenance release fixes an RBAC authorization bypass. It also updates the Go toolchain used to compile binaries to go 1..
Check if affected (1)
security
RBACauthorization bypass fixApplies if you use
RBAC.
AI-analyzed release notes for CNCF graduated and incubating projects.
A security maintenance release fixes an RBAC authorization bypass. It also updates the Go toolchain used to compile binaries to go 1..
Check if affected (1)
securityRBAC authorization bypass fix
Applies if you use RBAC.
OpenFeature core/v0.15.5 is a maintenance release with operator-relevant corrections and a security-related dependency update. The security announcement does not identify a specific advisory in the release text.
Action needed (1)
securityOpen Dependabot security alerts resolved
Open Dependabot security alerts were resolved in the OpenFeature core release.
This release resolves open Dependabot security alerts in the flagd proxy. The release note does not identify which vulnerabilities or dependencies were fixed.
Action needed (1)
securityDependabot security alerts resolved
The flagd-proxy/v0. release resolves open Dependabot security alerts. The release note does not identify the affected dependencies or vulnerabilities.
v3.3.9 is a maintenance release with a disclosed security fix and a go version update to resolve CVEs. It also includes bug fixes in the release.
Action needed (2)
securitycriticalGHSA-3v3m-wc6v-x4x3 security fix
This release fixes the vulnerability identified by GHSA-3v3m-wc6v-x4x3.
securityThe go version update for CVE resolution
The go version is bumped to resolve CVEs in v3.3.9.
Version v3. includes a disclosed security fix and additional correctness and dependency updates. The security fix is the release change that concerns users evaluating whether to upgrade.
Action needed (1)
securitycriticalSecurity fix for GHSA-3v3m-wc6v-x4x3
Version v3. contains a security fix for the vulnerability identified by GHSA-3v3m-wc6v-x4x3.
A broad feature and maintenance release adds routing, streaming, tracing, backup and restore, observability, and tablet-management capabilities alongside correctness, performance, and dependency updates. Operators should review changed defaults, backup behavior, removed endpoints and metrics, deprecated features, and security fixes affecting external decompression.
Action needed (3)
securityClear-text logging of sensitive information
The release addresses a code scanning alert about clear-text logging of sensitive information.
securityDirectory traversal protection in GetBackups
The file backup storage GetBackups RPC no longer permits directory traversal paths.
breakingStricter VTGate SELECT list validation
VTGate rejects an unqualified * after a comma in a SELECT list.
Check if affected (12)
securityOpt-in compressor commands from MANIFEST
Applicability is not stated in the release notes.
securityExternal decompressor commands from backup MANIFEST
Applies if you use backup storage.
securityBackup MANIFEST path traversal protection
Applies if backupengine runs.
Plan ahead (4)
deprecatedThe glog deprecationremoval planned in v25
Applies if you use glog.
deprecatedThe OpenTracing backend deprecationsremoval planned in v25
Applies if you use opentracing-jaeger or opentracing-datadog.
deprecatedVTOrc Snapshot Topology deprecationremoval planned in v25
Applies if you configure --snapshot-topology-interval.
v1.17.2 contains correctness fixes and a security-related Alpine base-image dependency update. The alpine update requires upgrading to receive the new base image.
Action needed (1)
securityThe alpine base image, updated to alpine:3.
The base image alpine has been updated from alpine:3. to alpine:3. to address security concerns. The update ships in v1.17.2.
A maintenance release includes corrected operator and scheduler behavior, along with an updated Alpine base image. The Alpine update addresses security concerns.
Action needed (1)
securityThe alpine base image, updated
The base image alpine was updated from alpine:3. to alpine:3. to address security concerns. The update ships in the release.
A security maintenance release with fixes affecting three Backstage catalog packages. The affected packages are @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, and @backstage/plugin-catalog-unprocessed-entities.
Check if affected (1)
securitySecurity fixes for Backstage catalog packages
Applies if you use any of @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, or @backstage/plugin-catalog-unprocessed-entities.
A release with operator-facing fixes, new capabilities, API and configuration changes, and dependency updates. It also includes fixes for CVE-2026-32597 in PyJWT and CVE-2026-30922 in pyasn1.
Action needed (3)
securityhighCVE-2026-32597 PyJWT validation fix
PyJWT crit header validation was fixed for CVE-2026-32597.
securityhighCVE-2026-30922 pyasn1 fix
The pyasn1 dependency was updated to address CVE-2026-30922 and its denial-of-service vulnerability.
breakingRequired MaxReplicas field
MaxReplicas is now required and must use the int32 type.
Check if affected (2)
breakingRemoval of the scheduler cert-hash restart annotation
Applies if you configure cert-hash.
breakingPYTHONPATH blocked by ISVC and ServingRuntime webhooks
Applies if you configure PYTHONPATH.
A substantial feature and maintenance release with new operator capabilities plus configuration, Helm, and CLI improvements. It also includes defect, output, dependency, and security fixes, including remediation for several CVE-related issues.
Action needed (4)
securityhighIntermediate certificate limit for CVE-2026-32280
Intermediate certificates are limited to mitigate CVE-2026-32280 in this release.
securityhighGo toolchain upgraded to 1. for CVE-2026-32283
The Go toolchain is upgraded to 1. to fix CVE-2026-32283.
securitymediumgo-tuf/v2 upgraded to v2. for CVE-2026-24686
go-tuf/v2 is upgraded to v2. to fix CVE-2026-24686.
securityStandard library CVE fixes
Standard library CVEs are fixed in this release.
Check if affected (2)
breakingRestricted ConfigMap access for namespaced policies
Applies if you use namespaced policies.
breakingFinalizers and uninstall workarounds removed
Applies if uninstall runs.
A security-focused maintenance release fixes two vulnerabilities in node attestation and join token handling. Operators should use this release to receive these fixes.
Check if affected (2)
securityThe aws_iid attestation identity verification
Applies if you use the aws_iid server node attestor plugin.
securityJoin token data store deletion
Applicability is not stated in the release notes.
This is a security and correctness fix release for SPIRE node attestation. It addresses forged EC2 identity handling in aws_iid and concurrent join-token attestation behavior.
Check if affected (1)
securityCorrected aws_iid EC2 identity verification
Applies if you use the aws_iid server node attestor plugin.
A maintenance release with a security fix, correctness fixes, a performance improvement, and dependency and toolchain manifest updates. Most changes take effect through the release itself without additional operator action.
Action needed (1)
securityBearer JWT disclosure fix in /connz
The /connz monitoring endpoint no longer discloses bearer JWTs. The fix ships in the NATS monitoring endpoint.
A maintenance release updates the Go toolchain and corrects NATS server defects. It includes fixes for bearer credential disclosure through monitoring and for redaction of route and cluster URL secrets.
Check if affected (2)
securityThe /connz endpoint no longer discloses bearer JWTs
Applies if you use the /connz monitoring endpoint.
securityMonitoring redaction of route and cluster URL secrets
Applies if you pass route and cluster URL secrets as command line arguments.
A security maintenance release with corrections for credential exposure, request decoding validation, and stored cross-site scripting. Advisory identifiers are provided for the addressed defects, and the fixes ship in this release.
Check if affected (3)
securityhighAzureAD remote write OAuth client_secret exposure fix
Applies if you use AzureAD remote write.
securityhighRemote-read decoded-length validation
Applies if you use Remote-read.
securitymediumOld UI heatmap chart le label escaping
Applies if you use the old UI heatmap chart.
This release updates the Go toolchain alongside changes to authorization behavior. The Go update addresses standard library vulnerabilities documented in the Go 1.26.2 release notes.
Action needed (1)
securityThe Go toolchain version, updated to 1.
The toolchain Go version is updated to 1. to address Go standard library vulnerabilities documented in the Go 1.26.2 release notes.
A security-focused release with fixes for exposed OAuth secrets and stored XSS. Remote read and write request validation now rejects snappy-compressed payloads whose declared decoded length exceeds the decode limit.
Check if affected (4)
securityhighAzureAD remote write client_secret exposure fixed
Applies if you use AzureAD remote write.
securityhighRemote-read decoded-length validation
Applies if you use Remote-read.
securitymediumOld UI heatmap chart le label escaping
Applies if you use UI.
This is primarily a security-focused Flatcar release with a large set of disclosed Linux fixes. It also includes a QEMU launcher performance correction and updates to Linux and ca-certificates dependencies.
Action needed (1)
securitycriticalLinux security fixes
Linux is updated with fixes for the disclosed advisories, including CVE-2023-52435, the CVE-2025-* and CVE-2026-* advisories listed for this release. The fixes ship in Flatcar lts-4081..
A security- and maintenance-focused release with updates to Linux and bundled components, along with dependency updates. It also corrects minimal-initrd regressions and changes service startup, SSH defaults, kernel-module availability, and other operator-visible behavior and layout.
Action needed (18)
securitycriticalLinux security updates
Linux was updated with security fixes associated with advisories including CVE-2024-56757, CVE-2025-71239, and CVE-2026-31788.
securityhighcurl security updates
curl was updated with fixes for CVE-2025-10148 and CVE-2025-9086.
securityhighexpat security update
expat was updated with a fix for CVE-2025-59375.
securityhighgnupg security updates
gnupg was updated with fixes for CVE-2025-68972 and CVE-2025-68973.
securityhighGo security updates
go was updated with security fixes associated with CVE-2025-47910, CVE-2025-47912, CVE-2025-58183, and related advisories.
securityhighintel-microcode security updates
intel-microcode was updated with fixes associated with CVE-2024-28956, CVE-2024-43420, CVE-2025-20012, and related advisories.
securityhighlibxslt security updates
libxslt was updated with fixes for CVE-2025-7424 and CVE-2025-7425.
securityhighnvidia-drivers security updates
nvidia-drivers was updated with fixes for CVE-2025-23280, CVE-2025-23282, CVE-2025-23300, and related advisories.
securityhighopenssl security updates
openssl was updated with fixes for CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232.
securityhighPAM security updates
pam was updated with fixes for CVE-2024-10041, CVE-2024-10963, CVE-2024-22365, and CVE-2025-6020.
securitymediumbinutils security updates
binutils was updated with fixes for CVE-2025-5244, CVE-2025-5245, and CVE-2025-8225.
securitymediumcoreutils security update
coreutils was updated with a fix for CVE-2025-5278.
securitymediumlibpcre2 security update
libpcre2 was updated with a fix for CVE-2025-58050.
securitymediumnet-tools security update
net-tools was updated with a fix for CVE-2025-46836.
securitylowopenssh security updates
openssh was updated with fixes for CVE-2025-61984 and CVE-2025-61985.
securitylibxml2 update
libxml2 was updated to libxml2-20250908.
breakingOpenSSH algorithm configuration defaults
Ciphers, MACs, and KexAlgorithms were dropped from the sshd configuration. OpenSSH upstream defaults are used instead.
breakingReduced first-stage initrd kernel modules
The set of kernel modules available in the first initrd is reduced.
Check if affected (1)
breakingAutomatic startup for overlaybd sysext services
Applies if you use the overlaybd sysext.
This release adds the Val map type, Linux glibc GPU builds, and updates to wasmtime and its rustls dependency. It also corrects pooling allocator probing and includes a security update for rustls-webpki.
Action needed (1)
securityrustls-webpki security update, RUSTSEC-2026-0049
The release includes a security update for rustls-webpki, addressing RUSTSEC-2026-0049.
This release updates the Go toolchain in Crossplane to 1.. The change addresses undisclosed standard-library CVEs.
Action needed (1)
securityThe Go toolchain, updated to 1.
Crossplane v1.20.7 updates the Go toolchain to 1.. The update addresses undisclosed standard-library CVEs.
A release with breaking configuration and flag changes, many new extension and protocol capabilities, and fixes for security, correctness, and observability. The recorded additions include module and filter extension APIs, MCP and A2A protocol support, OpenSSL builds, new formatters and metrics, and expanded streaming and TLS capabilities.
Action needed (1)
securityhighnghttp2 **CVE-2026-27135** patch
The nghttp2 **CVE-2026-27135** patch is included.
Check if affected (6)
securityURL encoding for query_parameter_mutations values
Applies if you configure query_parameter_mutations.
securityRBAC concatenation-based bypass prevention
Applies if RBAC runs.
breakingExplicit max_early_data_bytes configuration
Applies if you configure upstream_connect_mode with a value other than IMMEDIATE and do not configure max_early_data_bytes.
Plan ahead (1)
deprecatedThe enforce_rsa_key_usage option, deprecatedremoval date not announced
Applies if you configure enforce_rsa_key_usage.
A security-fix release with fixes for multiple CVEs and updates to affected dependencies. It also changes the default HTTP behavior and restricts configmap access for namespaced policies.
Action needed (12)
securitycriticalCVE-2025-68121 fix
This release fixes CVE-2025-68121.
securitycriticalCVE-2026-33186 fix
This release fixes CVE-2026-33186.
securityhighCVE-2026-24051 fix
This release fixes CVE-2026-24051 in the 1.16 release line.
securityhighThe github. dependency update
The github. dependency is updated to resolve CVE-2025-15558.
securityhighCVE-2025-66564 fix
This release resolves CVE-2025-66564.
securitymediumThe sigstore/rekor dependency update to v1.
The sigstore/rekor dependency is updated to v1. to fix CVE-2026-23831.
securitymediumThe go-tuf/v2 dependency update to v2.
The go-tuf/v2 dependency is updated to v2. to address CVE-2026-23992.
securitymediumCVE-2026-22772 fix
This release fixes CVE-2026-22772.
securitymediumThe go-tuf/v2 dependency update to v2.
The go-tuf/v2 dependency is updated to v2. to patch CVE-2026-24686.
securitylowCVE-2026-1229 fix
This release fixes CVE-2026-1229 in the 1.16 release line.
securitylowCVE-2026-26958 fix
This release fixes CVE-2026-26958.
securityStandard library CVE fixes
This release fixes standard library CVEs.
Check if affected (3)
securitycriticalHTTP disabled by default in namespaced policies
Applies if you configure namespaced policies.
securityCVE fixes for go < 1.
Applies if you depend on go < 1..
breakingRestricted configmap access for namespaced policies
Applies if you configure namespaced policies.
A maintenance release with multiple correctness fixes and security fixes, including changes for several CVEs and standard library CVEs. Operators should account for the changed HTTP default and narrower configmap access in addition to the security fixes.
Action needed (6)
securitycriticalCVE-2026-33186 correction
The release fixes CVE-2026-33186.
securityhighCVE-2026-24051 correction
The release fixes CVE-2026-24051 in the 1.17 release line.
securityhighCVE-2026-34986 correction
The release fixes CVE-2026-34986.
securitylowCVE-2026-1229 correction
The release fixes CVE-2026-1229.
securityCVES 2026-15558 correction
The release includes the CVES 2026-15558 fix for 1.17.
securityGo version update
The Go version was bumped to fix standard library CVEs.
Check if affected (2)
securitycriticalHTTP default for namespaced policies
Applies if you configure namespaced policies.
breakingConfigmap access for namespaced policies
Applies if you configure namespaced policies.
A maintenance release that adds operator-facing options and transport, plugin, and protocol support while correcting defects. It is built with Go 1., which contains fixes for disclosed CVEs; other changes concern operators using the affected features or behaviors.
Action needed (1)
securitycriticalGo 1. build with security fixes
The release is built with Go 1., which includes security fixes for CVE-2026-32282, CVE-2026-32289, CVE-2026-33810, CVE-2026-27144, CVE-2026-27143, CVE-2026-32288, CVE-2026-32283, CVE-2026-27140, CVE-2026-32936, CVE-2026-33190, CVE-2026-33489, CVE-2026-32934, and CVE-2026-35579.
Check if affected (1)
breakingOversized DoH GET query parameter rejection
Applies if you use DoH.
This release contains security-related updates to Go dependencies and the Go toolchain. It concerns deployments that rely on the affected dependencies or the bundled Go toolchain.
Action needed (2)
securityGo dependencies with reported vulnerabilities updated
Go dependencies with reported vulnerabilities are updated in cert-manager v1.19.5.
securityThe go toolchain updated to 1.25.8
The go toolchain is updated to 1.25.8 in cert-manager v1.19.5 to address reported vulnerabilities.
A release with a fix for Lua code injection, a required Envoy version change, and an Envoy dependency update. It is tested against Kubernetes 1.32 through 1.34.
Check if affected (2)
securityhighCVE-2026-41246 fix for cookieRewritePolicies[].
Applies if you use HTTPProxy resources.
breakingEnvoy 1.35.0 minimum version
Applies if you depend on Envoy.
Contour v1.32.5 fixes a Lua code injection vulnerability and upgrades Envoy to v1.34.14. The release also includes an informational Kubernetes compatibility update.
Action needed (1)
securityhighCVE-2026-41246 Lua code injection vulnerability fixed
This release fixes CVE-2026-41246 and GHSA-x4mj-7f9g-29h4, a Lua code injection vulnerability affecting cookieRewritePolicies[]..
This release fixes a Lua code injection vulnerability in Contour's Cookie Rewriting feature and updates Envoy to v1.. It is tested against Kubernetes 1.30 through 1.32.
Check if affected (1)
securityhighLua code injection fix for CVE-2026-41246
Applies if you configure cookieRewritePolicies[]..
Crossplane v2.2.1 includes security-focused dependency updates and a move to Go 1.25.9. It also corrects operator-facing behavior around dependency upgrades with ImageConfig prefix rewrites and resource selectors, and bumps Crossplane Runtime to v2.2.1.
Action needed (10)
securityThe github. module, updated to v1.6.3
Crossplane v2.2.1 updates the github. module to v1.6.3 as a security dependency change.
securityThe go. module, updated to v1.43.0
Crossplane v2.2.1 updates the go. module to v1.43.0 as a security dependency change.
securityThe github. module, updated to v4.1.4
Crossplane v2.2.1 updates the github. module to v4.1.4 as a security dependency change.
securityThe github. module, updated to v3.0.5
Crossplane v2.2.1 updates the github. module to v3.0.5 as a security dependency change.
securityThe github. module, updated to v5.17.1
Crossplane v2.2.1 updates the github. module to v5.17.1 as a security dependency change.
securityThe github. module, updated to v29.2.0+incompatible
Crossplane v2.2.1 updates the github. module to v29.2.0+incompatible as a security dependency change.
securityGo 1.25.9
Crossplane v2.2.1 updates Go to 1.25.9 as a security dependency change.
securityThe github. module, updated to v0.5.1
Crossplane v2.2.1 updates the github. module to v0.5.1 as a security dependency change.
securityThe github. module, updated to v2.0.6
Crossplane v2.2.1 updates the github. module to v2.0.6 as a security dependency change.
securityThe github. module, updated to v5.18.0
Crossplane v2.2.1 updates the github. module to v5.18.0 as a security dependency change.
Crossplane v2.1.5 combines correctness fixes with dependency and Go toolchain updates. The release includes updated versions of several modules used by Crossplane.
Action needed (10)
securityThe github. module, updated to v1.6.3
Crossplane v2.1.5 updates the github. module to v1.6.3.
securityThe google. module, updated to v1.79.3
Crossplane v2.1.5 updates the google. module to v1.79.3.
securityThe go. module, updated to v1.43.0
Crossplane v2.1.5 updates the go. module to v1.43.0.
securityThe github. module, updated to v4.1.4
Crossplane v2.1.5 updates the github. module to v4.1.4.
securityThe Go toolchain, updated to 1.25.9
Crossplane v2.1.5 updates the Go toolchain to 1.25.9.
securityThe github. module, updated to v5.17.1
Crossplane v2.1.5 updates the github. module to v5.17.1.
securityThe github. module, updated to v0.5.1
Crossplane v2.1.5 updates the github. module to v0.5.1.
securityThe github. module, updated to v2.0.6
Crossplane v2.1.5 updates the github. module to v2.0.6.
securityThe github. module, updated to v29.2.0+incompatible
Crossplane v2.1.5 updates the github. module to v29.2.0+incompatible.
securityThe github. module, updated to v5.18.0
Crossplane v2.1.5 updates the github. module to v5.18.0.
Crossplane v2.0.8 corrects two operator-visible defects and updates Go plus several dependencies. The dependency changes are marked for security, but the disclosures identify only the affected components rather than specific advisory IDs.
Action needed (9)
securityThe github. module update
The github. module is updated to v1. in Crossplane v2.0.8.
securityThe OTLP HTTP trace exporter module update
The go. module is updated to v1. in Crossplane v2.0.8.
securityThe github. module update
The github. module is updated to v4. in Crossplane v2.0.8.
securityThe Go version update to 1.
Go is updated to 1. in Crossplane v2.0.8.
securityThe github. module update to v5.
The github. module is updated to v5. in Crossplane v2.0.8.
securityThe github. module update
The github. module is updated to v0. in Crossplane v2.0.8.
securityThe github. module update
The github. module is updated to v29. in Crossplane v2.0.8.
securityThe github. module update
The github. module is updated to v2. in Crossplane v2.0.8.
securityThe github. module update to v5.
The github. module is updated to v5. in Crossplane v2.0.8.
Crossplane v1. is a dependency-focused release with updates to several Go modules, including security-marked changes. It also includes an update to crossplane-runtime v1..
Action needed (5)
securityThe github. module, updated to v1.
The github. module is updated to v1. in Crossplane v1.. The release note marks this dependency update as security-related.
securityThe go. module, updated to v1.
The go. module is updated to v1. in Crossplane v1.. The release note marks this dependency update as security-related.
securityThe github. module, updated to v5.
The github. module is updated to v5. in Crossplane v1.. The release note marks this dependency update as security-related.
securityThe github. module, updated to v0.
The github. module is updated to v0. in Crossplane v1.. The release note marks this dependency update as security-related.
securityThe github. module, updated to v5.
The github. module is updated to v5. in Crossplane v1.. The release note marks this dependency update as security-related.
This is a security-focused maintenance release. It corrects a service-invocation ACL mismatch caused by path normalization and updates Go to v1. for CVE coverage.
Action needed (2)
securityNormalized service-invocation ACL and outbound dispatch paths
The normalized path form is used for both the ACL check and outbound dispatch, removing the mismatch in service invocation.
securityThe Go dependency, updated to v1.
The Go dependency is updated to v1. to address CVEs affecting the 1.24 line.
This release contains a security fix for service-invocation access-control policy handling. It aligns method-path normalization for ACL checks and outbound dispatch, which concerns operators using these policies.
Action needed (1)
securityService-invocation ACL path normalization
In Dapr v1.17.5, the normalized method path is used for both the service-invocation ACL check and outbound dispatch, eliminating the mismatch that caused the bypass.
A security-focused release fixes a service-invocation ACL bypass caused by inconsistent path normalization. It also rejects dangerous method-path characters, removes the purell dependency from ACL path handling, and applies additional path cleaning in constructRequest.
Action needed (3)
securityConsistent service-invocation method path normalization
Method paths are normalized at the service invocation edge for HTTP and gRPC public API calls, gRPC internal calls, and proxied calls. The normalized form is used for both the ACL check and outbound dispatch.
securityStricter method path validation
Normalization uses path. to resolve . segments and duplicate slashes. Method paths containing #, ?, null bytes, or control characters are rejected.
securityThe purell dependency, removed from the ACL path
The purell dependency has been removed from ACL path handling.
Cilium v1.19.3 combines operator-relevant bug fixes with configuration and CLI additions, along with dependency and image updates. The release is relevant to deployments using the affected functionality and to users tracking dependency changes.
Action needed (1)
securityThe github. module update
The github. module is updated to v4.1.4 in the v1.19.3 release. The update is marked as security-related.
Cilium v1.18.9 contains correctness fixes and dependency updates. It also includes security-related changes, including an injection-prevention fix and a security-tagged module update.
Action needed (2)
securityRegex dollar-sign escaping for injection prevention
Regex handling now escapes the $ character to prevent injection. The fix ships in Cilium v1.18.9.
securityThe github. dependency update
The github. module is updated to v4.1.4 in Cilium v1.18.9. The release note marks this dependency update as security-related.
Keycloak 26.6.1 is a maintenance release with two described security fixes in the core. It also contains dependency updates, an enhancement, and bug fixes.
Action needed (2)
securitymediumCVE-2026-4366, blind server-side request forgery via HTTP redirect handling
Keycloak 26.6.1 fixes blind server-side request forgery through HTTP redirect handling in core.
securitylowCVE-2026-4633, user enumeration via identity-first login
Keycloak 26.6.1 fixes user enumeration through identity-first login in core.