This Linkerd edge release updates the OpenSSL and tower-http dependencies and ships Linkerd proxy version 2.353.0. No functional changes, security advisories, or operator actions are identified.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with security updates, including a dependency update tied to an advisory. It also includes compatibility and runtime changes across storage, policy, sandbox, validation, and toolchain areas.
Action needed (2)
securityhighCVE-2026-46680 security update
The release records CVE-2026-46680, also identified as GHSA-fqw6-gf59-qr4w, as a security update in containerd.
securityhigh
go-jose/go-joseupdated tov4.1. 4 The
go-jose/go-josedependency was updated tov4.to fix GHSA-78h2-9frx-2jm8, also identified as CVE-2026-34986.1. 4
wasmCloud v2.2.0 adds runtime, CLI, routing, API, and interface-publishing capabilities and corrects handling for musl-on-glibc systems. The release notes provided here disclose no security changes or operator actions.
Source ↗A maintenance release with a disclosed security fix, a narrower default socket policy, expanded compatibility for volatile mount options and AppArmor, and several correctness fixes. It also includes updates to container event handling, tar extraction, OCI USER validation, sandbox field forwarding, and event topics.
Action needed (1)
securityhighThe CVE-2026-46680 security fix
A security fix for CVE-2026-46680, also identified as GHSA-fqw6-gf59-qr4w, ships in this release.
Check if affected (1)
breakingThe default
seccompsocket policyApplies if you use
seccomp.
containerd v1.7.32 includes a disclosed security advisory alongside correctness and compatibility fixes. The release concerns users assessing security exposure or changes in runtime and configuration behavior.
Action needed (1)
securityhighCVE-2026-46680 security fix
containerd v1.7.32 includes a fix associated with CVE-2026-46680 and GHSA-fqw6-gf59-qr4w.
A maintenance release focused on runtime correctness and security, including fixes across snapshotter, storage, and server components. It also contains compatibility changes and updates to the API and Go toolchain.
Action needed (1)
securityhighCVE-2026-46680 correction
The fix for CVE-2026-46680 ships in this release.
Check if affected (1)
breakingThe
overlayfs"rebase" capability, disabled in user namespacesApplies if you use
overlayfsand run in a user namespace.
Plan ahead (1)
deprecatedTask fields in Runc options, deprecated
Applies if you configure task fields in Runc options.
Release v1.16.0 adds datastore timeout configuration and additional tracing output. It also fixes defects in experimental weighted_graph_check and OIDC authentication, and updates the Go toolchain for standard-library vulnerability fixes.
Action needed (1)
securityThe
Gotoolchain, updated to 1.26.3The toolchain now uses
Goversion1.to address vulnerabilities in the26. 3 Gostandard library. This update ships in v1.16.0.
This containerd release corrects a defect in sandbox task API endpoints for non-runc runtimes. The recorded release material identifies the fix in the highlights and overview.
Source ↗NATS v2.14.1 is a maintenance release with dependency and toolchain updates, monitoring additions, behavioral improvements, and correctness fixes. The release has no security advisories or explicitly described security vulnerabilities.
Source ↗NATS v2.12.9 adds monitoring metrics and broadens acceptance of client TLS certificates with DNS subject alternate names. It also changes several operational behaviors, improves performance, and fixes defects across General, Leafnode, JetStream, Raft, storage, and MQTT functionality. No security advisories or explicitly security-related fixes are disclosed.
Source ↗Flux v2.8.8 is a maintenance release with defect corrections, expanded compatibility, and dependency updates. It also includes two disclosed security fixes in go-git.
Action needed (1)
securitymediumThe
go-gitsecurity fixes for CVE-2026-45571 and CVE-2026-45570Flux v2.8.8 includes security fixes in
go-gitassociated with CVE-2026-45571, CVE-2026-45570, GHSA-crhj-59gh-8x96, and GHSA-m7cr-m3pv-hgrp.
Emissary v4.1.0 updates the Envoy dependency from 1.36.2 to 1.37.2. It also fixes stale cached entries when an empty-delta snapshot is received, addressing the Istio mTLS certificate-rotation failure described in #4744.
Source ↗A broad release with breaking API removals, changed defaults and constraints, and many new operator-facing capabilities. It also includes performance improvements and an explicitly described dependency security update.
Action needed (2)
securityModule Federation packages at
v2.3. 3 Module Federation packages were upgraded to
v2.to address known vulnerabilities.3. 3 breakingThe
@remixicon/reactversion constraintThe
@remixicon/reactdependency is limited to versions below4.because of a license change.9. 0
Check if affected (9)
securitySpecific defaults for known MCP clients
Applies if you configure
CIMDorDCR.breakingThe
NavItemBlueprintAPI, removedApplies if you use
NavItemBlueprint.breakingSidebar and legacy
nav-itemrendering inrenderInTestAppApplies if you use
renderInTestApp.- + 6 more on the release page
Plan ahead (4)
deprecatedThe
PolicyQueryUser.field, deprecatedidentity Applies if you use
PolicyQueryUser..identity deprecatedThe
EXPERIMENTAL_formDecoratorsfield, deprecated aliasApplies if you configure
EXPERIMENTAL_formDecorators.deprecatedThe
catalog.setting, deprecatedstitchingStrategy. mode: 'immediate' Applies if you configure
catalog..stitchingStrategy. mode - + 1 more on the release page
A maintenance release that adds exporter in-flight request monitoring and configuration-validation APIs while correcting runtime and configuration behavior. It also changes Prometheus telemetry defaults for explicitly configured metrics and deprecates older validation APIs.
Check if affected (2)
breakingThe
max_request_body_sizelimit for snappy requestsApplies if you configure
max_request_body_size.breakingPrometheus exporter defaults for explicitly configured telemetry
Applies if you configure the telemetry metrics section.
Plan ahead (1)
deprecatedThe
xconfmap.andValidator confmap.APIsValidate Applies if you use
xconfmap.orValidator confmap..Validate
SPIRE v1.15.0 adds operator capabilities, changes CLI and output behavior, and updates dependencies. It also fixes correctness issues, with no security advisory or vulnerability disclosed.
Source ↗A maintenance release with numerous disclosed security fixes, dependency updates, enhancements, and bug fixes. It also corrects forced object deletion during the operator upgrade path.
Action needed (6)
securityhighCVE-2026-33871: HTTP/2 CONTINUATION frame flood denial of service
The release fixes the
HTTP/2CONTINUATIONframe flood denial-of-service issue identified by CVE-2026-33871.securityhighCVE-2026-33870: HTTP request smuggling through chunked extension parsing
The release corrects the HTTP request smuggling primitive caused by chunked extension quoted-string parsing, identified by CVE-2026-33870.
securityhighBouncycastle updates for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598
The release updates bouncycastle for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598.
securityhighCVE-2026-7504: Redirect URI validation bypass
The release corrects the redirect URI validation bypass in Keycloak, identified by CVE-2026-7504.
securitymediumCVE-2026-5588: Bouncy Castle
bcpkixcryptographic algorithm vulnerabilityThe release updates the
bcpkixmodules affected by the broken or risky cryptographic algorithm vulnerability in the Bouncy Castle Crypto Package for Java, identified by CVE-2026-5588.securityPermission and policy call ordering in
admin/apiThe release corrects the ordering of permission and policy calls in
admin/apithat led to exposure of a client ID.
Check if affected (12)
securityhighCVE-2026-7307: Denial of service at the
/samlendpointApplies if you use
/saml.securityhighCVE-2026-7571: Access token disclosure and implicit flow bypass
Applies if you use
implicit flow.securityhighCVE-2026-7507: Session fixation in the OIDC login flow
Applies if you use
OIDC login flow.- + 9 more on the release page
A feature and maintenance release that adds HAMi-core, Ascend and vNPU virtualization, DRA, CDI, monitoring, metrics, deployment, and debugging capabilities. It also includes scheduling, allocation, device, chart, and compatibility fixes, security updates, dependency upgrades, and removal of a deprecated scheduler policy ConfigMap.
Action needed (3)
securityThe
tensorflow/tensorflowdependency, upgradedThe
tensorflow/tensorflowdependency was upgraded from 2.20.0rc0-gpu to 2.21.0rc0-gpu in this release.securityThe
tensorflow/tensorflowdependency, upgraded againThe
tensorflow/tensorflowdependency was upgraded from 2.21.0rc0-gpu to 2.21.0rc1-gpu in this release.securityThe
golangdependency, upgradedThe
golangdependency was upgraded for a security issue in this release.
Check if affected (3)
breakingThe deprecated
scheduler policy configmap, removedApplies if you configure
scheduler policy configmap.breakingThe Helm
nvidia.defaultoverwriteEnv Applies if you use Helm.
breakingHost networking for the
device plugin, disabledApplies if the
device pluginruns.
HAMi v2.8.3 is a bug-fix release. It addresses GPU memory information handling, HAMi-core monitoring, and device utilization watcher startup behavior.
Source ↗A maintenance release with dependency updates, operator-visible configuration and behavior changes, new integrations and capabilities, and correctness fixes. It also includes an explicitly disclosed security-related Go dependency upgrade.
Action needed (1)
securityhighGo dependency upgrades for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986
Go dependencies were upgraded to address GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.
Check if affected (2)
breakingThe
provider configsource, changedApplies if you configure
provider config.breakingThe
MCP_SERVER_ENABLEDdefault, changed tofalseApplies if you use the MCP server.
A feature release adds Gateway API, ambient-mode, telemetry, Helm, and operability capabilities. Authenticated XDS debug endpoints and the new default image registry are the changes most likely to affect deployment and operational configuration.
Action needed (1)
breakingDefault Istio image registry
The default registry for Istio images is now
registry..istio. io
Check if affected (1)
breakingAuthentication required for XDS debug endpoints
Applies if
ENABLE_DEBUG_ENDPOINT_AUTHis set.
A maintenance release adds Gateway API compatibility, analyzer and HBONE tuning capabilities, and fixes certificate, controller, probe, output, and authorization issues. The authorization fixes address cross-namespace configuration access and regex handling in AuthorizationPolicy.
Action needed (1)
securityCross-namespace access to
istio.andio/debug/syncz istio.io/debug/config_dump Authorization is fixed so an authenticated workload cannot enumerate proxies or retrieve configuration dumps for workloads in other namespaces through
istio.andio/debug/syncz istio..io/debug/config_dump
Check if affected (2)
securityRegex handling in
AuthorizationPolicyidentity fieldsApplicability is not stated in the release notes.
breakingThe
AMBIENT_ENABLE_AWS_BRANCH_ENI_PROBEsetting and kubelet health probesApplies when ambient mesh pods run on AWS EKS and use Security Groups for Pods (branch ENI).
A maintenance release that adds Gateway API v1.4.1 support and new diagnostics and configuration controls while fixing several correctness issues. It also includes two described security fixes for XDS debug endpoint authorization and regex handling in AuthorizationPolicy.
Action needed (1)
securitySame-namespace authorization for
StatusGenXDS debug endpointsThe
StatusGen-served XDS debug endpointsistio.andio/debug/syncz istio.now enforce same-namespace authorization for non-system callers. Authenticated workloads can no longer enumerate proxies or retrieve configuration dumps for workloads in other namespaces.io/debug/config_dump
Check if affected (1)
securityEscaped regex metacharacters in
AuthorizationPolicyidentity fieldsApplies if you configure
source.orprincipals source..namespaces
Litmus 3.29.0 includes operator-facing changes across dependencies and platform behavior. This release includes a google. update to v1. for CVE-2026-33186.
Action needed (1)
securitycriticalThe
google.dependency, updated for CVE-2026-33186golang. org/grpc The release updates
google.togolang. org/grpc v1.. The dependency update addresses CVE-2026-33186 in Litmus 3.29.0.79. 3
A maintenance release with fixes for cluster-scoped resource generation in GeneratingPolicy and AdmissionRequest handling for mutate existing policy.
Source ↗A release focused on a security fix and API evolution. It tightens the Updater() contract and begins preparation for removal of an existing module.
Action needed (1)
securitymediumGHSA-qp9x-wp8f-qgjj fixed
The release fixes GHSA-qp9x-wp8f-qgjj.
Check if affected (1)
breakingThe
Updater()bootstrap argument, now requiredApplies if you use
Updater().
Plan ahead (1)
deprecatedPreparation for removal of
securesystemslib.hash Applies if you use
securesystemslib..hash
This release updates the lifecycle bundled into newly created builders and corrects trusted-builder inspection. It also adds a trusted Heroku builder, with a future recommendation change announced.
Source ↗Dapr v1.17.7 is a corrective release focused on workflow, scheduler, actor, networking, and pub/sub reliability defects. It also adds workflow payload metrics, changes scheduler defaults, adds a scheduler flag, and updates github..
Check if affected (1)
breakingThe actor
drainOngoingCallTimeoutconstraintApplies if an application supplies an actor
drainOngoingCallTimeoutthat meets or exceeds the daprd-side placement dissemination timeout, which defaults to 30 seconds.
A release that changes the default sidecar mode and promotes native sidecars to GA. It also fixes correctness issues, adds configurable timestamp handling, addresses eleven disclosed CVEs, and updates numerous dependencies.
Action needed (2)
securityhighEleven disclosed CVEs, fixed
The release fixes eleven disclosed CVEs: CVE-2026-42501, CVE-2026-42499, CVE-2026-39836, CVE-2026-39826, CVE-2026-39825, CVE-2026-39823, CVE-2026-39820, CVE-2026-39819, CVE-2026-39817, CVE-2026-33814, and CVE-2026-33811.
breakingThe
config.default, changedlinkerd. io/proxy-enable-native-sidecar The default sidecar mode changes through
config., making native sidecars the default.linkerd. io/proxy-enable-native-sidecar
A maintenance release updates the bundled lifecycle version in pack CLI builders and refreshes Go dependencies. The notes also include upgrade prerequisites.
Source ↗Helm v3.21.0 is a maintenance release with dependency updates and fixes to chart and OCI handling. It also includes a security fix in the opentelemetry packages.
Action needed (1)
securityThe
opentelemetrypackages, upgraded for CVE patchesHelm v3.21.0 upgrades the
opentelemetrypackages to patch CVEs.
A feature and maintenance release with new template and CLI capabilities, dependency updates, flag deprecations, and numerous correctness fixes. It also includes security fixes for plugin path traversal and GO-2026-4394.
Action needed (1)
securityhigh
go.update foropentelemetry. io/otel/sdk GO-2026-4394Helm v4.2.0 updates
go.to v1.40.0 foropentelemetry. io/otel/sdk GO-2026-4394.
Check if affected (1)
securityPlugin version path traversal fix
Applies if you use the
Pluginextension.
Plan ahead (1)
deprecatedThe
--hide-notesand--render-subchart-notesflags, deprecatedApplies if you use
--hide-notesor--render-subchart-notes.
A maintenance release with operator-visible bug fixes, narrower EndpointSlice watch behavior, new Helm configurability, and dependency and image updates. It also includes a security-related dependency update without a disclosed advisory identifier.
Action needed (2)
securityThe
github.dependency updatecom/moby/spdystream The security-related
github.dependency is updated to v0.5.1.com/moby/spdystream breakingService-label filtering for
EndpointSlicewatchesThe
loadbalancer/reflectorscomponent now filtersEndpointSlicewatches by service labels.
Check if affected (1)
breakingService-label filtering for
EndpointSlicesApplies if
--k8s-service-proxy-nameis set.
A maintenance release with an enforced policy behavior change, bug fixes, new metrics, and Helm image overrides. It also updates dependencies and container images and refreshes container image manifests.
Action needed (1)
securityThe
github.dependency updatecom/moby/spdystream The
github.module is updated tocom/moby/spdystream v0.in v1.17.16.5. 1
Check if affected (1)
breaking
CiliumLocalRedirectPolicyaddressMatcheroverride behaviorApplies if you use
addressMatcherinCiliumLocalRedirectPolicyand do not enable--enable-lrp-address-matcher-override=true.
Cilium v1.18.10 contains correctness fixes, Helm support for overriding images, and dependency and image updates. The github. update is marked as a security update, but no advisory identifier is provided.
Action needed (1)
securityThe
github.module update to v0.5.1com/moby/spdystream Cilium v1.18.10 updates the
github.module to v0.5.1 as an undisclosed security update.com/moby/spdystream
A release with breaking removals, API and metric changes, bug corrections, and experimental capabilities. It also adds storage, MCP, UI, and tracing functionality, with no security advisories or security-specific fixes disclosed.
Action needed (2)
breakingThe
min step apiinmetricstore, removedThe
min step apiwas removed frommetricstorein this release.breakingThe non-standard health MCP tool, removed
The non-standard health MCP tool was removed from
jaegermcpin this release.
A maintenance release that closes the 3.2 series and marks it as end of life. It also contains an operator-visible bug fix and a dependency update.
Plan ahead (1)
deprecatedThe
3.reaches end of life2 release series Applies if you use the
3..2 release series
This release combines bug fixes with dependency and toolchain updates. The Go update to 1. addresses CVEs and concerns deployments using this release.
Action needed (1)
securityThe
Gotoolchain, updated to1.25. 9 The
Gotoolchain is updated to1.on25. 9 release-3.to resolve CVEs.3
Argo CD v3.4.2 is a maintenance release with bug fixes, dependency updates, and corrected secret handling in server-side diff results. It contains no listed security advisories, and no operator action beyond upgrading is identified.
Source ↗A maintenance release with bug and regression corrections across Kubernetes components, including DRA metadata handling, kubelet startup, Windows networking, kube-proxy, and kubeadm. No security advisories or operator actions beyond upgrading are stated.
Source ↗A maintenance release with operator-facing bug corrections in scheduling, networking, kubeadm, kube-proxy, and metric behavior. No security advisories or security-specific fixes are disclosed.
Source ↗