This Linkerd release contains dependency version updates. No functional or security changes are stated, and the dependency updates are applied as part of the release without operator setup changes.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
This release updates dependencies and component versions across Linkerd. It also corrects resource labels in policy-k8s outbound indexer logs.
Source ↗This Linkerd edge release updates the OpenSSL and tower-http dependencies and ships Linkerd proxy version 2.353.0. No functional changes, security advisories, or operator actions are identified.
Source ↗A release that changes the default sidecar mode and promotes native sidecars to GA. It also fixes correctness issues, adds configurable timestamp handling, addresses eleven disclosed CVEs, and updates numerous dependencies.
Action needed (2)
securityhighEleven disclosed CVEs, fixed
The release fixes eleven disclosed CVEs: CVE-2026-42501, CVE-2026-42499, CVE-2026-39836, CVE-2026-39826, CVE-2026-39825, CVE-2026-39823, CVE-2026-39820, CVE-2026-39819, CVE-2026-39817, CVE-2026-33814, and CVE-2026-33811.
breakingThe
config.default, changedlinkerd. io/proxy-enable-native-sidecar The default sidecar mode changes through
config., making native sidecars the default.linkerd. io/proxy-enable-native-sidecar
This release narrows Kubernetes support to version 1.31 or newer. It also adds multicluster gateway configuration, reduces destination-controller memory usage, corrects namespace-aware service cleanup, and updates third-party dependencies.
Check if affected (1)
breakingMinimum supported
Kubernetesversion, 1.31Applies when your cluster runs
Kubernetesolder than1..31 The minimum supported
Kubernetesversion for this release and future releases is1..31