RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jun 2026Clear ×
Tektonv1.6.3CI/CD & App DeliveryJun 15, 2026

Tekton v1.6.3 contains resolver validation and behavior corrections, along with fixes affecting cross-architecture execution and metrics. It also updates dependencies, including a gRPC change for CVE-2026-33186, so resolver users and dependency-sensitive deployments should review the release.

Action needed (1)

  • securitycriticalThe google.golang.org/grpc dependency fix for CVE-2026-33186

    The google.golang.org/grpc dependency includes a fix for CVE-2026-33186 in v1.6.3.

Check if affected (1)

  • breakingTekton Resolver target restrictions

    Applies if your ResolutionRequest objects use Tekton Resolvers.

Source
Tektonv1.3.5CI/CD & App DeliveryJun 15, 2026

A correctness-focused release fixes resolver behavior and updates dependencies. It also narrows the resolver input contract and changes pod metrics and labels.

Action needed (1)

  • breakingPod label removal

    The pod label is removed in this release.

Check if affected (1)

  • breakingThe Resolver API resolution scope

    Applies if you use custom resolvers and the Resolver API.

Source
Tektonv1.2.1CI/CD & App DeliveryJun 15, 2026

Nothing here needs operator attention. The release note contains installation and attestation information, with no described operator-facing changes.

Source
Kubeflow26.03.1AI & MLJun 15, 2026

A calendar-versioned release with a breaking dashboard upgrade requirement, updated components and dependencies, new defaults, and fixes for deployment and configuration defects. Security hardening is included, but no specific vulnerability or advisory is disclosed.

Action needed (2)

  • breakingmodel-registry UI enabled by default

    The model-registry UI is enabled by default in this release.

  • breakingTwo dex replicas without a sticky service

    dex runs two replicas without a sticky service by default in this release.

Check if affected (1)

  • breakingBreaking dashboard upgrade requirement

    Applies if you use the dashboard.

Source
KServev0.19.0AI & MLJun 14, 2026

A release with operator-facing additions and fixes, including new LLMInferenceService capabilities and status observability. It also updates dependencies and images and includes security-related fixes.

Action needed (1)

  • securityhighazure-core pinned for CVE-2026-21226

    The azure-core dependency is pinned to >=1.38.0 to address CVE-2026-21226.

Check if affected (3)

  • securityvllm setup and pillow dependency fixes

    Applies if you depend on vllm or pillow.

  • breakingIncorrect CRDs removed from llmisvc-crd

    Applies if you use llmisvc-crd.

  • breakingHelm imagePullPolicy defaults

    Applies if you use Helm.

Source
Helmv4.2.1Kubernetes CoreJun 12, 2026

Helm v4.2.1 is a maintenance release with correctness fixes and dependency updates. It includes an update to golang.org/x/net that addresses GO-2026-5026.

Action needed (1)

  • securitycriticalThe golang.org/x/net dependency update for GO-2026-5026

    Helm v4.2.1 updates golang.org/x/net to v0.55.0 to address GO-2026-5026.

Source
Helmv3.21.1Kubernetes CoreJun 12, 2026

Helm v3.21.1 includes dependency and toolchain updates alongside fixes for correctness issues. The disclosed dependency update affects releases using golang.org/x/net.

Action needed (1)

  • securitycriticalThe golang.org/x/net dependency, updated for GO-2026-5026

    Helm v3.21.1 bumps golang.org/x/net to v0.55.0 to address GO-2026-5026.

Source
Kubernetesv1.36.2Kubernetes CoreJun 12, 2026

A maintenance release with Go 1.26.4 build updates and correctness and performance fixes across scheduling, kubelet volume handling, suspended Jobs, Secret data, endpoint processing, and kubeadm dry-run certificate copying. No security advisories are disclosed.

Source
Kubernetesv1.35.6Kubernetes CoreJun 12, 2026

A maintenance release with correctness and performance fixes, along with an updated Go toolchain dependency. The recorded notes do not disclose security advisories or security-specific flaws.

Source
Kubernetesv1.34.9Kubernetes CoreJun 12, 2026

A maintenance release with a Go 1.25.11 toolchain update and fixes for several operator-facing defects. The listed fixes address controller, storage, node, and kubeadm behavior.

Source
Kubernetesv1.33.13Kubernetes CoreJun 12, 2026

A maintenance release updates the Go build dependency to Go 1.25.11 and fixes an endpoint-controller panic when processing services with an empty IPFamilies field. No other operator action is indicated by the available release details.

Source
Daprv1.16.15Orchestration & ManagementJun 11, 2026

A maintenance release with a correctness fix for Sentry startup when Ed25519 or RSA issuer keys are used. It also includes a dependency version update.

Source
Falco0.44.1SecurityJun 11, 2026

Adds a capability to disable BPF iterators and fixes multiple BPF-iterator issues through a library dependency update to 0.25.4. No security issue is disclosed.

Source
Envoyv1.38.2Networking & MessagingJun 10, 2026

This maintenance release adds HTTP/2 runtime controls and corrects runtime guard override handling. It also announces future removal of the HTTP/2 histogram feature and its runtime guard.

Plan ahead (1)

  • deprecatedFuture removal of envoy.reloadable_features.http2_record_histogramsremoval date not announced

    Applies if envoy.reloadable_features.http2_record_histograms is enabled.

Source
Envoyv1.37.4Networking & MessagingJun 10, 2026

This release adds HTTP/2 header-statistics histograms and a cookie-size limit, and fixes RTDS runtime guard override removal. The HTTP/2 histogram runtime guard is planned for removal in a future Envoy release.

Plan ahead (1)

  • deprecatedThe envoy.reloadable_features.http2_record_histograms histograms and runtime guard, planned for future removalremoval date not announced

    Applies if you use envoy.reloadable_features.http2_record_histograms.

Source
Envoyv1.36.8Networking & MessagingJun 10, 2026

A maintenance release corrects RTDS runtime-guard override behavior and adds opt-in HTTP/2 cookie and header capabilities. The existing HTTP/2 histogram capability and its runtime guard are announced for future removal.

Plan ahead (1)

  • deprecatedenvoy.reloadable_features.http2_record_histograms, future removalremoval date not announced

    Applies if you use envoy.reloadable_features.http2_record_histograms.

Source
Daprv1.18.0Orchestration & ManagementJun 10, 2026

A substantial operator-facing release adds workflow and MCP capabilities alongside control-plane, API, component, and lifecycle changes. It also includes security fixes, dependency and default updates, and compatibility constraints that affect upgrade planning and configuration review.

Action needed (8)

  • securitymediumThe golang.org/x/image dependency update for GO-2026-4962

    golang.org/x/image is updated to v0.39.0 for GO-2026-4962.

  • securityThe durabletask-go and pgx dependency updates

    durabletask-go is updated to v0.12.1, and pgx is updated as part of the vulnerability fixes.

  • breakingThe WorkflowsRemoteActivityReminder default, enabled

    WorkflowsRemoteActivityReminder is enabled by default. Cross-app workflow activity results are delivered through Scheduler reminders unless the setting is changed.

  • breakingThe HotReload default, enabled

    HotReload is enabled by default for Components, Subscriptions, MCPServers, Configurations, HTTPEndpoints, Resiliencies, and WorkflowAccessPolicies.

  • breakingSidecar probe defaults

    Sidecar probe defaults now give liveness more time before a kubelet restart, at about 230 seconds, while readiness responds more quickly.

  • breakingThe HotReload default, enabled in v1.18

    HotReload is enabled by default in v1.18.

  • breakingLiveness and readiness probe defaults

    The default liveness probe is widened, and the readiness probe default is tightened.

  • breakingChanged sidecar probe defaults

    Sidecar probe defaults now set liveness to be more lenient, at about 230 seconds before a kubelet restart, and readiness to be tighter, at about 3 seconds for the control plane and 5 seconds for daprd.

Check if affected (6)

  • securityService invocation path traversal ACL bypass fix

    Applies if you use service invocation.

  • breakingThe MCPServerResource and WorkflowAccessPolicy feature gates, removed

    Applies if you configure the MCPServerResource or WorkflowAccessPolicy feature gates.

  • breakingThe Sentry Ed25519 workload identity key rollback constraint

    Applicability is not stated in the release notes.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedThe ScheduleJobAlpha1 alpha RPCs, deprecated

    Applies if you use ScheduleJobAlpha1.

Source
Envoyv1.35.12Networking & MessagingJun 10, 2026

Envoy v1.35.12 contains an RTDS runtime-guard correction and opt-in HTTP/2 statistics and cookie-size controls. No security advisories or security-specific fixes are disclosed.

Source
Backstagev1.51.2CI/CD & App DeliveryJun 10, 2026

A maintenance release includes a fix for an empty userSelect value in the msgraph module, which caused all users to be dropped. No other operator action is indicated.

Source
Chaos Meshv2.8.3ObservabilityJun 10, 2026

A security-focused maintenance release includes undisclosed container-image CVE fixes and updates image components. It also corrects NetworkChaos recovery for targets in CrashLoopBackOff by falling back to the sandbox (pause) container PID for network namespace operations.

Action needed (2)

  • securityGo toolchain and containerd upgrades

    The Go toolchain (1.25.11) and containerd (1.7.32) were upgraded in the container images.

  • securitymemStress rebuild and headless JRE for chaos-daemon

    The memStress helper was rebuilt with the modern Go toolchain (v0.3.1), and the chaos-daemon image switched to a headless JRE.

Source
Crossplanev2.3.2Orchestration & ManagementJun 9, 2026

Crossplane v2.3.2 changes XR rendering and requirement handling, fixes stable sorting of resource references, and updates the crossplane-runtime dependency. It concerns releases that use these rendering, requirement, sorting, or dependency paths.

Source
NATSv2.12.11Networking & MessagingJun 9, 2026

A feature and behavior release for JetStream and server operations, with new capabilities alongside changed defaults and downgrade constraints. Operators using strict JetStream requests, insecure TLS cipher suites, or new v2.12 features should review the changed behavior; the release also fixes a JetStream regression.

Check if affected (3)

  • breakingInsecure TLS cipher suite default

    Applies if you enable allow_insecure_cipher_suites.

  • breakingJetStream strict mode default

    Applies if you use JetStream.

  • breakingDowngrade compatibility for new v2.12 features

    Applies if you use new v2.12 features.

Source
CoreDNSv1.14.4Kubernetes CoreJun 9, 2026

A release with new plugin capabilities, stricter validation, DNS and cache behavior changes, expanded platform support, and malformed-input handling fixes. The HTTP/3 request header limit is narrowed for DoH3.

Check if affected (1)

  • breakingBound DoH3 HTTP/3 request header size

    Applies if you use DoH3.

Source
OpenTelemetryv0.154.0ObservabilityJun 8, 2026

This release adds configuration options, changes how the --skip-get-modules flag handles go.mod, and extends numeric validator handling in generated config structs. It also fixes a nil-pointer panic during sending_queue::batch unmarshalling.

Source
KEDAv2.20.1Orchestration & ManagementJun 8, 2026

KEDA v2.20.1 is a maintenance release focused on operator-visible correctness. The documented fixes affect concurrent scaling behavior and scaler-watch event reporting.

Source
gRPCv1.81.1Networking & MessagingJun 8, 2026

A maintenance release with correctness fixes in EventEngine and completion queue shutdown behavior on Windows and weak memory models. It also changes the default availability of the error_flatten experiment; an internal implementation change has no operator-facing impact.

Check if affected (1)

  • breakingThe error_flatten experiment, enabled by default

    Applicability is not stated in the release notes.

Source
Open Policy Agent (OPA)v1.17.1SecurityJun 8, 2026

A security-focused maintenance release updates the Go toolchain used to build official OPA binaries to address two disclosed standard-library vulnerabilities affecting OPA's HTTP handler and crypto builtins. Users who build their own binaries or images manage the Go version themselves.

Action needed (1)

  • securitymediumThe Go 1.26.4 build toolchain update

    OPA is built with Go 1.26.4 in this release. The update fixes standard-library vulnerabilities used by OPA's HTTP handler and crypto builtins, identified as GO-2026-5037 and GO-2026-5039.

Source
Crossplanev1.20.9Orchestration & ManagementJun 5, 2026

This Crossplane release combines dependency maintenance with a new CLI check for upgrade readiness. The check scans a live v1.x control plane for features removed or changed in Crossplane v2 and reports what would break before an upgrade.

Action needed (1)

  • securityThe golang.org/x/net module, updated to v0.55.0

    The golang.org/x/net module is updated to v0.55.0 in Crossplane v1.20.9. The release note marks this dependency update as security-related, but does not identify a specific vulnerability.

Source
Cortexv1.21.1ObservabilityJun 5, 2026

A maintenance release with operator-facing security fixes and configuration changes across ingestion, distribution, and status pages. It also includes fixes for request handling, authentication, configuration exposure, gossip limits, and client and runtime panics.

Check if affected (3)

  • securityStored XSS protection in Alertmanager and Store Gateway status pages

    Applies if you run Alertmanager or Store Gateway.

  • securityWrappedHistogram native histogram size limit

    Applies if you use native histograms.

  • breakingDecompressed gzip output limit for ParseProtoReader and OTLP ingestion

    Applies if you use the OTLP ingestion path.

Source
OpenFGAv1.17.1SecurityJun 5, 2026

OpenFGA v1.17.1 combines correctness fixes with security-related Go toolchain and image dependency updates. The security updates address Go standard library vulnerabilities in the toolchain and released images.

Action needed (2)

  • securityThe Go toolchain, updated to 1.26.4

    OpenFGA v1.17.1 updates the Go toolchain version to 1.26.4 to address Go standard library vulnerabilities.

  • securitygrpc-health-probe updated to v0.4.52

    Released images update grpc-health-probe to v0.4.52, rebuilt with Go 1.26.4, so they no longer ship the Go standard library vulnerabilities addressed by this update.

Source
Linkerdedge-26.6.1Networking & MessagingJun 5, 2026

Linkerd edge-26.6.1 fixes an HTTP body size-limit defect and updates several dependencies and the proxy component. No security advisories or security-specific flaws are described.

Source
Istio1.29.4Networking & MessagingJun 4, 2026

A maintenance release with a security fix for Envoy and operator-relevant correctness fixes across Istio ambient, gateway, routing, and CNI behavior. It also adds automatic fallback from the nftables backend to iptables when the bundled nft binary lacks JSON support.

Action needed (1)

  • securityhighCVE-2026-47774 Envoy memory exhaustion fix

    CVE-2026-47774 fixes an Envoy memory exhaustion issue in which specially crafted HTTP/2 requests could bypass request header size accounting and trigger excessive memory use. The fix ships in Envoy.

Source
Istio1.28.8Networking & MessagingJun 4, 2026

A maintenance release with a disclosed Envoy denial-of-service fix and additional correctness fixes. The security fix addresses memory exhaustion from specially crafted HTTP/2 requests, while the other corrections do not require setup changes.

Action needed (1)

  • securityhighThe Envoy denial-of-service vulnerability CVE-2026-47774, fixed

    CVE-2026-47774 fixes an Envoy denial-of-service vulnerability in which specially crafted HTTP/2 requests could cause excessive memory consumption. The fix accounts for cookie header bytes during request header size validation and limits total decoded header size in HPACK processing.

Source
Istio1.30.1Networking & MessagingJun 4, 2026

A maintenance release with an Envoy denial-of-service security fix, defect corrections, new operator-facing capabilities, a dependency update, and removal of a feature-gate guard. The security fix addresses disclosed advisory CVE-2026-47774.

Action needed (1)

  • securityhighCVE-2026-47774 Envoy denial-of-service fix

    The fix addresses CVE-2026-47774 in Envoy, where specially crafted HTTP/2 requests could exhaust process memory because decoded header size was not fully limited during request validation.

Check if affected (1)

  • breakingPILOT_ENABLE_ALPHA_GATEWAY_API guard removed from ListenerSet

    Applies if you use the ListenerSet API.

Source
Envoyv1.38.1Networking & MessagingJun 4, 2026

A maintenance release with HTTP/2 protections, an nghttp2 patch, and an OAuth2 HMAC verification fix. It also changes router response-body output and EDS batch load-balancer rebuild defaults, while the release notes include crash fixes in OAuth2 token-cookie decryption and dynamic HTTP filters.

Action needed (1)

  • securityhighnghttp2 patch for CVE-2026-27135

    The nghttp2 dependency includes the patch for CVE-2026-27135. The patched dependency ships in v1.38.1.

Check if affected (4)

  • securityhighHTTP/2 header-limit enforcement and cookie accounting

    Applies if you use HTTP/2 and do not enable envoy.reloadable_features.http2_include_cookies_in_limits.

  • securityOAuth2 HMAC verification timing side-channel fix

    Applies if you use oauth2.

  • breakingRouter transport-failure reason response body

    Applies if you use the router and do not enable envoy.reloadable_features.hide_transport_failure_reason_in_response_body.

  • + 1 more on the release page
Source
Keycloak26.6.3SecurityJun 4, 2026

A security-focused maintenance release with fixes spanning OIDC, authorization and account APIs, identity features, federation, WebAuthn, SAML, Netty, and lodash. It also updates dependencies and adds startup and SPI behavior alongside numerous correctness fixes.

Action needed (2)

  • securityhighCVE-2026-4800 lodash code injection

    CVE-2026-4800 is addressed in the account UI, where lodash was vulnerable to code injection.

  • securitymediumCVE-2026-42581 Netty HTTP/1.0 smuggling sanitization

    CVE-2026-42581 is addressed in Netty, correcting HTTP/1.0 TE and CL coexistence that bypassed smuggling sanitization.

Check if affected (15)

Source
Envoyv1.37.3Networking & MessagingJun 4, 2026

A maintenance release with three security fixes and additional correctness fixes. The security changes affect HTTP/2 header-limit handling, oauth2 HMAC verification, and nghttp2; other recorded fixes address token-cookie decryption and ADS stream shutdown cleanup.

Action needed (1)

  • securityhighCVE-2026-27135 fix in nghttp2

    Envoy applies the nghttp2 patch for CVE-2026-27135.

Check if affected (2)

  • securityhighHTTP/2 header limits and cookie accounting

    Applies if you use HTTP/2.

  • securityoauth2 HMAC verification timing-side-channel fix

    Applies if you use oauth2.

Source
Envoyv1.36.7Networking & MessagingJun 4, 2026

Envoy v1.36.7 is a security-focused update with changes to HTTP/2 handling and OAuth2 authentication. It also includes an nghttp2 security patch, so deployments using these components are directly affected.

Action needed (1)

  • securityhighThe nghttp2 CVE-2026-27135 patch

    Envoy v1.36.7 applies the nghttp2 patch for CVE-2026-27135 in its HTTP/2 handling.

Check if affected (2)

  • securityhighHTTP/2 header-limit enforcement and cookie accounting

    Applies if you use HTTP/2 with configured header list or request-header limits.

  • securityOAuth2 HMAC verification timing side-channel fix

    Applies if you use the OAuth2 filter.

Source
Envoyv1.35.11Networking & MessagingJun 3, 2026

Envoy v1.35.11 is a security-focused release with fixes in HTTP/2, OAuth2, and nghttp2. It also includes ordinary bug fixes and new statistics capabilities, while the security changes are the ones that require upgrading.

Action needed (1)

  • securityhighThe nghttp2 CVE-2026-27135 patch

    Envoy v1.35.11 applies the nghttp2 patch for CVE-2026-27135.

Check if affected (2)

  • securityhighHTTP/2 header limits and cookie accounting

    Applies if you use HTTP/2 request header limits.

  • securityOAuth2 HMAC verification timing protection

    Applies if you use OAuth2 HMAC verification.

Source
KubeVirtv1.8.3Orchestration & ManagementJun 3, 2026

A maintenance release with a fix for symlink traversal, a gRPC dependency update addressing GHSA-p77j-4mvh-x3m3, and deprecated recording rules. It also contains correctness fixes across VM status reporting, device resource handling, live migration, alerts, and VM operations.

Action needed (2)

  • securitycriticalgoogle.golang.org/grpc update to 1.79.3

    The google.golang.org/grpc dependency is bumped to 1.79.3 to remediate GHSA-p77j-4mvh-x3m3.

  • securitySymlink traversal fix in the VMExport directory handler

    The VMExport directory handler is fixed to prevent symlink traversal.

Plan ahead (1)

  • deprecatedDeprecated kubevirt_vm_created_total and kubevirt_vm_created_by_pod_total recording rules

    Applies if you use kubevirt_vm_created_total or kubevirt_vm_created_by_pod_total.

Source
← NewerOlder →
Browse by month