A maintenance release focused on bug and regression corrections across Kubernetes components. The listed changes affect node startup, networking, kube-proxy, kubeadm initialization and joining, kubelet authorization, and etcd health checks.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with operator-facing bug corrections in scheduling, networking, kubeadm, kube-proxy, and metric behavior. No security advisories or security-specific fixes are disclosed.
Source ↗A maintenance release with correctness fixes in networking, scheduling, kubeadm, and metrics behavior. No security advisories or operator actions are explicitly identified.
Source ↗A maintenance release focused on kubeadm bug fixes. The remaining release-note sections are headings or empty sections without an operator-facing change.
Source ↗Flux v2. includes a security update to the go-git dependency alongside toolkit component updates. The go-git update addresses CVE-2026-45022 and GHSA-389r-gv7p-r3rp.
Action needed (1)
securityhighThe
go-gitdependency update tov5.19. 0 The
go-gitdependency is updated tov5., which fixes CVE-2026-45022 and addresses GHSA-389r-gv7p-r3rp. This update ships in Flux19. 0 v2..8. 7
OPA v1.16.2 is a security-focused maintenance release. It updates the Go version used to build OPA binaries and images to 1. to address vulnerabilities.
Action needed (1)
securityThe
Gobuild version, updated to1.26. 3 The version of
Goused to build OPA binaries and images is updated to1.to address vulnerabilities.26. 3
This is a security-focused Flatcar release with disclosed Linux security fixes. It also updates the Linux and ca-certificates dependencies.
Action needed (1)
securitycritical
Linuxsecurity updates, including CVE-2026-31733Linuxreceives security updates in Flatcarstable-4593., including CVE-2026-31733 and the other disclosed2. 1 Linuxadvisories listed for this change.
OpenTelemetry v0.152.0 adds exporter observability and configuration/API capabilities while correcting bugs in request handling, telemetry, and value formatting. It also deprecates older configuration validation APIs in favor of the confmap APIs.
Plan ahead (1)
deprecatedThe
xconfmap.andValidator confmap.APIs, deprecatedValidate Applies if you use
xconfmap.or the deprecatedValidator confmap.API for configuration validation.Validate
Harbor v2.14.4 contains fixes to session and integration behavior, along with updates to its dependency and toolchain versions and base image. No security advisories or explicitly described vulnerabilities are present.
Source ↗A maintenance release with a security fix for a disclosed denial-of-service vulnerability in the webhook server, plus ordinary scheduling bug fixes. The vulnerability affects webhook servers that accept unbounded HTTP request bodies.
Check if affected (1)
securitymediumCVE-2026-44247 in the
Volcano webhook serverApplies if the
Volcano webhook serverruns.
Volcano v1.13.3 includes a security fix for a denial-of-service vulnerability in the webhook server. It also contains other defect corrections.
Check if affected (1)
securitymediumCVE-2026-44247 in the Volcano webhook server
Applies if a pod can access the Volcano webhook endpoint over the network.
A maintenance release fixes a disclosed webhook denial-of-service vulnerability and corrects scheduler, queue, and event-handling defects. It also updates the Kubernetes version used by the webhook-manager image.
Check if affected (1)
securitymediumCVE-2026-44247: Webhook server request body handling
Applies if the Volcano webhook server runs.
Kubescape v4.0.8 adds a CLI flag and includes multiple correctness fixes, with most changes focused on VAP validation and output handling. No security advisories or security-specific fixes are disclosed.
Source ↗A maintenance release with operator-facing correctness fixes, new control and TLS configuration capabilities, narrower CRD scan-mode support, and interface simplifications. It also improves validation and error reporting, with no security advisories or vulnerability disclosures.
Check if affected (3)
breaking
protobuf content typeremovalApplies if you use
protobuf content type.breakingSidecar requirement removal
Applies if you use a
sidecar.breakingThe
--outputflag, removedApplies if you configure
--output.
This release removes the iRMC driver and legacy vbmctl entrypoint, deprecates BMH., and changes defaults and constraints. It also adds HostClaim and vbmctl capabilities, corrects bugs, and updates dependencies.
Action needed (1)
breakingManager TLS default set to unset
The manager TLS default is set back to unset in this release.
Check if affected (3)
breakingThe
iRMCdriver, removedApplies if you use the iRMC driver.
breaking
PreprovisioningImagerequired for deprovisioningApplies if cleaning is enabled.
breakingThe legacy
vbmctlentrypoint, removedApplies if you use the legacy vbmctl entrypoint.
Plan ahead (1)
deprecatedThe
BMH.field, deprecatedSpec. Firmware Applies if you configure
BMH..Spec. Firmware
A maintenance release with correctness fixes, dependency updates, and new deployment and plugin capabilities. It also removes the obsolete canary-v2 identifier.
Check if affected (1)
breakingThe
canary-v2canary identifier, removedApplies if you configure
canary-v2.
A maintenance release with a correctness fix that reverts a VTOrc flag addition. It also updates planner handling for merged DML IN and NOT IN subqueries.
Check if affected (1)
breakingThe
VTOrccell-watch flag, revertedApplies if
VTOrcruns.
A maintenance release with bug fixes, compatibility and behavior changes, operational improvements, metric updates, and two Go dependency upgrades. It includes no disclosed security advisories or explicitly security-related fixes.
Action needed (2)
breakingUnqualified
*rejection after commas inSELECTlistsvtgatenow rejects an unqualified*after a comma in aSELECTlist. The change ships in this release.breakingBare
*restriction in thesqlparsergrammarsqlparsernow enforces the restriction on bare*in its grammar. The change ships in this release.
Check if affected (1)
breaking
EmergencyReparentShardreplication-stop error validationApplies if you use
EmergencyReparentShard.
OpenFGA v1.15.1 is a correctness-focused release. The available release information points to fixes in command error handling, object listing, experimental graph checks, bounded tuple reads, and check request handling.
Source ↗Harbor v2.15.1 is a maintenance release with defect corrections, behavior changes, and dependency and base-image updates. It also updates photon packages to fix CVEs.
Action needed (1)
security
photon packagesCVE fixesThe
photon packagesare updated to fix CVEs in Harbor v2.15.1.
A broad maintenance and feature release with correctness, performance, dependency, and operator-facing changes. Operators should review the cluster-version annotation format and changed defaults, while dependency updates include Kubernetes and Helm changes; no explicitly disclosed exploitable vulnerability or security advisory is identified.
Action needed (4)
securityThe
k8s.module, updated toio/kubernetes v1.34. 2 The
k8s.module is updated toio/kubernetes v1.as a security-related dependency update.34. 2 securityThe
helmdependency, updated to3.19. 4 The
helmdependency is updated to3.due to a CVE.19. 4 breakinggRPC service config DNS TXT lookups, disabled by default
gRPC service config DNS TXT lookups are disabled by default.
breakingThe appset resource status count, defaulted to
5000The default appset resource status count is changed to
5000.
Check if affected (2)
breakingThe
--clientflag in the Helm version command, removedApplies if you use
--client.breakingThe cluster-version annotation format, renamed
Applies if you use Application Sets with Cluster Generators and configure
argocd..argoproj. io/auto-label-cluster-info
A feature and maintenance release adds OTA image preheating, K8s-on-K8s deployment, declarative YurtHub conversion, and new hub and YurtHub capabilities. It also removes or deprecates legacy components and fixes multiple defects, with no security advisories identified.
Check if affected (4)
breakingThe
YurtAppOverriderremovalApplies if you use
YurtAppOverrider.breakingThe
yurt-coordinatorremoval fromHelm chartsApplies if you use both
yurt-coordinatorandHelm charts.breakingThe
yurt-coordinator-cert controllerremoval fromyurt-managerApplies if you use both
yurt-coordinator-cert controllerandyurt-manager.- + 1 more on the release page
Plan ahead (2)
deprecatedThe
yurtmanager delegate lease controller, deprecatedApplies if you use
yurtmanager delegate lease controller.deprecatedThe
YurtAppDaemon controllerandYurtAppDaemon webhook, deprecatedApplies if you use
YurtAppDaemon controllerorYurtAppDaemon webhook.
CRI-O v1.36.0 is a substantive operator-facing feature and maintenance release with runtime and operational changes. It also includes a security update to spdystream and a broad dependency refresh.
Action needed (1)
securityhighThe
spdystreamdependency update for CVE-2026-35469CRI-O v1.36.0 updates the
spdystreamdependency to fix CVE-2026-35469.
Confidential Containers v0.20.0 combines operator-visible capability and compatibility updates with deprecations of several image and provider paths. It also includes a security fix identified by GHSA-q49m-57vm-c8cc.
Action needed (1)
securityhighGHSA-q49m-57vm-c8cc security fix
The release includes a fix for the security issue identified by GHSA-q49m-57vm-c8cc.
Plan ahead (3)
deprecatedThe Docker CAA provider, deprecatedremoval date not announced
Applies if you use the Docker CAA provider.
breakingThe
Fedora-based mkosi CAA podvm image, deprecatedremoval date not announcedApplies if you use the
Fedora-based mkosi CAA podvm image.deprecatedSupport for
packerimages, deprecatedremoval date not announcedApplies if you use packer images.
A maintenance release with corrected HTTP and workload behavior, dependency updates, and toolchain maintenance. It also removes canary-v2 in favor of canary.
Check if affected (1)
breakingThe
canary-v2configuration, removed in favor ofcanaryApplies if you configure
canary-v2.
A maintenance release that ends the 3. series on May 06th 2026, after which it will no longer receive bug fixes or security updates. It also includes a fix for an error when attempting a second delete operation.
Plan ahead (1)
deprecatedThe
3.release series, end of liferemoval planned in May 06th 20261 Applies if you run the
3.release series.1
Longhorn v1.11.2 contains operator-relevant defect fixes, a new setting for controlling CSIStorageCapacity reporting, and an optimization that reduces cluster-wide memory use by longhorn-manager Pod informer caching. Installation and upgrade requirements are prerequisites rather than release changes.
Source ↗A maintenance release that adds a runtime metric and a GOMAXPROCS configuration field, fixes two runtime defects, and reverts CNI monitoring after node bootstrapping regressions. It also updates the spdystream dependency to address CVE-2026-35469.
Action needed (2)
securityhighThe
spdystreamdependency update for CVE-2026-35469The
spdystreamdependency is updated to address CVE-2026-35469. The update ships in this release.breakingCRI-O CNI monitoring, reverted
CRI-O reverts CNI monitoring because it caused node bootstrapping regressions. The change ships in this release.
CRI-O v1.34.8 includes a security-relevant dependency update and adds operator-facing observability and configuration capabilities. The dependency update is the release change that requires upgrading, while the other additions concern optional setup or informational use.
Action needed (1)
securityhighCVE-2026-35469 fix in the
spdystreamdependencyCRI-O v1.34.8 updates the
spdystreamdependency to fix CVE-2026-35469.
CRI-O v1.33.12 includes a security fix for a disclosed vulnerability in the spdystream dependency. It also adds the min_injected_gomaxprocs configuration field for controlling the floor of injected GOMAXPROCS values.
Action needed (1)
securityhighCVE-2026-35469 fix in the
spdystreamdependencyCVE-2026-35469 is fixed by updating the
spdystreamdependency in CRI-O v1.33.12.
This release includes an operator-facing command-line behavior change, along with internal or build-related updates. No detailed change entry is available here for the operator-facing behavior.
Source ↗Kubescape v4.0.6 includes dependency upgrades, new Helm and Kustomize support, scan-metadata capabilities, and correctness fixes. No security advisory or explicitly described vulnerability is present.
Source ↗This release updates the lifecycle bundled into builders and corrects platform-specific builder image fetching for containerd-backed Docker daemons. The remaining release-note material describes headings or duplicate details of the same fix.
Source ↗A maintenance release with correctness fixes for HTTP errors, NATS subscription readiness, and WorkloadDeployment readiness, plus dependency and toolchain updates. It removes canary-v2 now that canary exists and includes dependency cleanup.
Action needed (1)
breakingThe
canary-v2option, removedcanary-v2is removed now thatcanaryexists. The removal ships in this release.
A maintenance release with a correctness fix, an RBAC authorization bypass fix, and a security-related dependency update for GO-2026-4962. It also records Go 1. as the toolchain used to build the binaries.
Action needed (1)
securitymedium
golang.update fororg/x/image GO-2026-4962The release updates
golang.toorg/x/image v0.to resolve39. 0 GO-2026-4962.
Check if affected (1)
securityRBAC authorization bypass in nested
PutrequestsApplies if you use
RBAC.
A maintenance release with a security fix for an RBAC authorization bypass in transaction handling. It also includes an ordinary correctness fix and a Go toolchain dependency update.
Action needed (1)
securityRBAC authorization bypass in nested etcd transactions
The release fixes an RBAC authorization bypass that allowed read access through
PrevKvor lease attachment inPutrequests nested in etcd transactions. The fix ships in this release.
A security maintenance release fixes an RBAC authorization bypass. It also updates the Go toolchain used to compile binaries to go 1..
Check if affected (1)
security
RBACauthorization bypass fixApplies if you use
RBAC.
This release narrows Kubernetes support to version 1.31 or newer. It also adds multicluster gateway configuration, reduces destination-controller memory usage, corrects namespace-aware service cleanup, and updates third-party dependencies.
Check if affected (1)
breakingMinimum supported
Kubernetesversion, 1.31Applies when your cluster runs
Kubernetesolder than1..31
This patch release fixes a plugin-manager regression that may cause the service to hang during shutdown. The change is relevant to deployments using the affected plugin manager behavior.
Source ↗A substantial operator-facing release with new capabilities, behavior changes, a compatibility constraint, and a deprecation. It is the first annual LTS release under a Kubernetes-aligned cadence, with support planned for at least two years.
Action needed (1)
breakingPlugin names disallow commas
OCI hook adjustments accumulate owners, and commas are disallowed in plugin names in this release.
Plan ahead (1)
deprecatedThe
shim.API, deprecatedCommand Applies if you use
shim..Command