A maintenance release updates grpc-go to v1.79.3 and grpc-health-probe to v0.4.47. It also corrects OTEL_EXPORTER_OTLP_ENDPOINT handling for URI schemes, including TLS activation for https:// endpoints.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
Linkerd edge-26.3.3 fixes a proxy restart defect and updates dependencies and shipped component versions. No security issue or operator configuration change is disclosed.
Source ↗A maintenance release with disclosed Go standard-library security fixes, a Go toolchain upgrade, and a required manual Configuration CRD update. It also adds RavenDB state-store registration and correctness and performance fixes across pub/sub, scheduling, service invocation, workflows, actors, conversation components, state stores, and Sentry.
Action needed (3)
securityhighGo toolchain upgrade to 1.25.8
The Go toolchain was upgraded from 1.24.13 to 1.25.8 across all modules and Docker images in the repository.
securitymedium
GO-2026-4603and escaped meta content URLshtml/templatenow escapes URLs in meta content attribute actions, addressing potential cross-site scripting via crafted URLs.securitylow
GO-2026-4602andos.root boundariesFileInfo os.can no longer escape from aFileInfo Rootto access files outside the intended directory boundary.
Check if affected (2)
securityhigh
GO-2026-4601and IPv6 host literal parsingApplies if you use
net/url.breaking
ConfigurationstateRetentionPolicyschemaApplies if you configure
stateRetentionPolicy.
A maintenance release updates the google. dependency from 1.78.0 to 1.79.3 and updates the Ansible operator plugin to 1.42.2. Generated-file maintenance and the section heading do not affect operators.
This release contains bug fixes and dependency and toolchain updates. No security advisories or explicitly described vulnerabilities are identified.
Source ↗Metal3-io v0.12.3 fixes two controller defects and updates several dependencies and the Go toolchain. No security advisories or security-specific fixes are identified.
Source ↗A security and maintenance release that fixes disclosed vulnerabilities alongside ordinary bugs. The security fixes require upgrading, while the other fixes require no operator action beyond upgrading.
Check if affected (8)
securitymediumCVE-2026-1180, blind SSRF in OIDC Dynamic Client Registration
Applies if you use
OIDC Dynamic Client Registration.securitymediumCVE-2025-14777, Keycloak IDOR in realm client creation and deletion
Applicability is not stated in the release notes.
securitymediumCVE-2026-3121, privilege escalation via
manage-clients permissionApplies if you configure
manage-clients permission.- + 5 more on the release page
A maintenance release with Kubeadm correctness fixes and an adjustment to DRA device taint eviction status behavior. It contains no identified security changes or operator actions.
Source ↗A kubeadm maintenance patch corrects defects in cluster lifecycle handling. The changes affect etcd client endpoints and reset-time unmounting of /var/lib/kubelet peer mounts.
A maintenance release focused on operator-facing bug fixes in admission validation and cluster lifecycle workflows. No security advisories, operator-actionable removals, default changes, or new constraints are described.
Source ↗Cloud Custodian 0.9.50.0 adds operator-facing resources, filters, actions, and configuration options across AWS, Azure, and GCP. It also corrects provider-specific defects and changes existing filtering and policy behavior, with no security advisories or explicit vulnerability fixes described.
Source ↗A maintenance release adds agent version reporting, changes TLS policy behavior, improves performance, and corrects several defects. It also includes security fixes for selector logging and TLS certificate chain validation.
Action needed (1)
securityAgent-level selector logging removal
Selectors are no longer logged at the agent level to avoid potential leakage of sensitive information.
Check if affected (1)
securityServer TCP endpoint TLS session tickets disabled
Applies if you use the server TCP endpoint.
Version 3.27.0 adds support for targeting Jobs in chaos experiments and removes the 1024-character limit on CMD probe commands. It also corrects runtime, synchronization, UI, and backend defects. No security advisories or security-specific fixes are disclosed.
Source ↗A breaking compatibility release changes defaults and removes or narrows support across the frontend, CLI, catalog, and integrations. It also introduces new frontend, catalog, scaffolder, CLI, and integration capabilities, while deprecated functionality remains in some areas and requires planning. The release contains no security fixes.
Check if affected (14)
breakingThe New Frontend System as the default for new apps
Applicability is not stated in the release notes.
breakingThe
create-appfrontend selection flagApplies if you use the
--nextflag forcreate-app.breakingDeprecated types and options
Applies if you use deprecated types and options.
- + 11 more on the release page
Plan ahead (7)
deprecatedDeprecated
variant,columns, andtableOptionspropsApplies if you use the
variant,columns, ortableOptionsprops.deprecatedThe
RelatedEntitiesCardcomponentApplies if you use
RelatedEntitiesCard.deprecatedThe
CLI built-in set fallbackApplicability is not stated in the release notes.
- + 4 more on the release page
A maintenance release with an updated OpenTelemetry SDK, a new --grype-db-url option for the Kubescape scan command, and a fix for missing-host handling. The remaining release-note entries are merge, heading, or internal logging changes.
A feature release that adds guest OS support, CLI capabilities, virtualization and synchronization features, template support, and a default hypervisor change for non-native architectures. The guest home directory moves from /home/${USER}. to /home/${USER}. with a compatibility symlink, and no security changes are disclosed.
Check if affected (1)
breaking
QEMUas the default hypervisor for non-native architecturesApplies if
QEMUruns on non-native architectures.
A maintenance release with operator-facing behavior fixes across backup handling, VMI updates, storage migration, and monitoring. It also updates the quiescing status indication used by KubeVirt.
Action needed (1)
breakingThe
QuiesceFailedindication replaced byQuiesceTimeoutThe
QuiesceFailedindication was replaced withQuiesceTimeout.
A maintenance release with a disclosed security fix, an indication rename for Windows VSS handling, and correctness, behavior, and observability updates. Most changes require no operator action beyond upgrading.
Action needed (1)
securityhighCVE-2025-47913 remediation
The release adds a replace directive that points
golang/x/cryptoto the patchedopenshift/golang-cryptomodule to remediate CVE-2025-47913.
Check if affected (2)
breaking
QuiesceFailedindication renamed toQuiesceTimeoutApplies if you use Windows VSS.
breaking
DefaultVirtWebhookClient{QPS,Burst}values alignedApplicability is not stated in the release notes.
Flux v2.8.3 fixes a helm-controller templating regression. The release also identifies helm-controller v1.5.3.
Source ↗Argo CD v3.3.4 includes signed container images, a fix that skips token refresh threshold parsing in unrelated components, and an otel-sdk dependency update. The release also contains CI-only work, headings, and installation examples without separately actionable operator impact.
An operator release with expanded configuration and LLMInferenceService capabilities, plus chart and dependency updates, behavior changes, removals, and defect corrections. It also includes security fixes for operators to review.
Action needed (13)
securitycritical
h11malformed-body fix for CVE-2025-43859h11malformed-body handling associated with CVE-2025-43859 is addressed in this release.securityhigh
starletteversion0.49. 1 starletteis pinned to version0.to fix CVE-2025-62727 in this release.49. 1 securityhigh
lightgbmversion4.6. 0 lightgbmis updated to version4.for CVE-2024-43598 in this release.6. 0 securityhighCVE-2025-66418 decompression-chain fix
The unbounded number of links in the decompression chain associated with CVE-2025-66418 is addressed in this release.
securityhigh
expr-lang/exprversionv1.17. 7 expr-lang/expris updated tov1.to fix CVE-2025-68156 in this release.17. 7 securityhigh
cryptographyfix for CVE-2026-26007The
cryptographyissue associated with CVE-2026-26007 is addressed in this release.securityhigh
python-multipartfix for CVE-2026-24486The arbitrary file write issue in
python-multipartassociated with CVE-2026-24486 is addressed in this release.securitymediumFixes for CVE-2025-22872, CVE-2025-47914, and CVE-2025-58181
This release addresses CVE-2025-22872, CVE-2025-47914, and CVE-2025-58181.
security
https.path traversal preventiongo The path traversal issue in
https.is prevented in this release.go securitySeveral CVE fixes
This release addresses several CVEs.
security
AIOHTTPHTTP Parserauto_decompressfixThe
AIOHTTPHTTP Parserauto_decompressfeature issue involving zip bombs is addressed in this release.security
extractTarFilespath traversal fixThe path traversal vulnerability in
extractTarFilesis addressed in this release.breaking
minioreplacement withseaweedfsminiois replaced withseaweedfsin this release.
Check if affected (6)
breaking
inferenceserviceCRD cert-manager annotation removalApplies if you use the
inferenceserviceCRD.breakingPython 3.9 support removal
Applies if you run Python 3.9.
breakingDeprecated
--disable-log-requestsflag removalApplies if you configure
--disable-log-requests.- + 3 more on the release page
A maintenance release updates builders to include lifecycle v0.21.0 and fixes lifecycle binary selection for amd64. It also adds ubi9, ubi10, and noble as suggested builders.
Source ↗A maintenance release adds gRPC message-size configuration, changes TLS certificate rotation handling, and updates an experimental default. It also tightens tuple validation, fixes correctness issues, and updates the Go toolchain for disclosed advisories.
Action needed (2)
securityhighGo toolchain version
1.25. 8 The Go toolchain is updated to version
1.to address standard library vulnerabilities identified by25. 8 GO-2026-4603andGO-2026-4601.breakingStricter tuple string validation
Tuple validation now fails when a tuple string contains Unicode control characters or null bytes.
Check if affected (1)
breakingThe
pipeline_list_objectsexperimental defaultApplies if you set
pipeline_list_objects, setlistObjects-pipeline-enabled, or use a custom featureflag client.
Longhorn v1.11.1 is a maintenance release with operator-relevant correctness fixes, CSI and V2 engine improvements, and compatibility changes. No security advisories or explicitly security-related flaws are disclosed.
Source ↗A maintenance release that narrows Kubernetes support to version 1.25 and newer and marks several older Kafka and extension components for removal. It adds Kafka 3.9.2 support and includes dependency updates addressing multiple CVEs and a GHSA advisory.
Action needed (8)
securityhighGRPC Netty Shaded update for CVE-2025-55163
GRPC Netty Shadedwas upgraded to remediate CVE-2025-55163.securitymedium
Zookeeperupdate for CVE-2024-47554The
Zookeeperdependency was upgraded to remediate CVE-2024-47554.securitymediumNimbus Jose JWT 10.0.2 update for CVE-2025-53864
Nimbus Jose JWTwas upgraded to version10.to remediate CVE-2025-53864.0. 2 securitymedium
Netty4.1.130.Final update for CVE-2025-67735Nettywas updated to version4.to resolve CVE-2025-67735.1. 130. Final securitymediumApache Log4J 2.25.3 update for CVE-2025-68161
Apache Log4Jwas updated to version2.to remediate CVE-2025-68161.25. 3 securitymedium
Vertx4.5.24 update for CVE-2026-1002Vertxwas updated to version4.to remediate CVE-2026-1002.5. 24 securitymedium
Jacksonupdate for GHSA-72hv-8253-57qqJacksonwas updated to address GHSA-72hv-8253-57qq.security
Vert.andx Nettydependency updatesThe
Vert.andx Nettydependencies were bumped on the0.branch to fix CVEs.45. x
Check if affected (1)
breaking
Kubernetessupport narrowed to 1.25 and newerApplies if you use
Kubernetes 1.or23 Kubernetes 1..24
Plan ahead (3)
breakingStrimzi MirrorMaker 2 Extensions deprecationdeprecated since 0.28.0 · removal planned in 0.46
Applies if you use the
Strimzi MirrorMaker 2 Extensions.breakingStrimzi EnvVar Configuration Provider inclusiondeprecated since 0.38.0 · removal planned in 0.46
Applies if you use the
Strimzi EnvVar Configuration Provider.deprecatedZooKeeper-based Kafka and MirrorMaker 1 supportremoval planned in 0.46
Applies if you use
ZooKeeper-based Apache Kafka clustersor MirrorMaker 1 deployments.
Flux v2.8.2 includes correctness fixes and dependency updates. It also fixes a disclosed TLS-handshake denial-of-service issue in the controller builds.
Action needed (1)
securitymediumCVE-2026-27138 TLS-handshake DoS fix
The TLS-handshake denial-of-service issue identified as CVE-2026-27138 is fixed by building all controllers with
Go 1..26. 1
This release narrows Linkerd Viz scraping behavior and adds the inbound_http_request_duration_seconds and inbound_grpc_request_duration_seconds metrics histograms. It also updates dependencies and ships proxy v2.342.0.
Check if affected (1)
breakingLinkerd Viz default scraping configuration
Applies if you use Linkerd Viz.
A maintenance release with fixes for chart value handling and OCI reference parsing, plus a Kubernetes dependency-group update.
Source ↗Helm v4. is primarily a maintenance release with defect corrections, dependency updates, and a change that aligns defaults. The explicitly identified security-related change updates the OpenTelemetry SDK for GO-2026-4394.
Action needed (1)
securityhighThe
go.dependency update foropentelemetry. io/otel/sdk GO-2026-4394The
go.dependency was updated toopentelemetry. io/otel/sdk v1.for40. 0 GO-2026-4394in Helmv4..1. 3
Dragonfly v2.4.3 is a dependency maintenance release with updates to five third-party dependencies and d7y.. No security advisory or operator-facing behavior change is described.
A security-focused maintenance release fixes undisclosed issues in two Backstage backend plugins. The affected plugins are @backstage/plugin-auth-backend and @backstage/plugin-scaffolder-backend.
Action needed (1)
securitySecurity fixes in two Backstage backend plugins
Security fixes ship in
@backstage/plugin-auth-backendand@backstage/plugin-scaffolder-backend.
This release expands Windows and device-management support while changing edge database and node-query behavior. It also updates Kubernetes and changes how consumers retrieve device status through the DeviceStatus CRD.
Check if affected (1)
breakingDevice status moved to the
DeviceStatus CRDApplies if you use the
Device CRD.
A maintenance release with security fixes for crashes, header handling, JSON memory writes, and downstream reset processing. It also includes ordinary bug fixes, updates to published artifacts, and a dynamic-module compatibility change.
Action needed (3)
securitymediumCVE-2026-26310 and GHSA-3cw6-2j68-868p: scoped IPv6 crash fix in
getAddressWithPort()The network
getAddressWithPort()path no longer crashes when called with a scoped IPv6 address. This release includes CVE-2026-26310 and GHSA-3cw6-2j68-868p.securitymediumCVE-2026-26309 and GHSA-56cj-wgg3-x943: JSON null-terminator write fix
The JSON handling code fixes an off-by-one write that could corrupt the string null terminator. This release includes CVE-2026-26309 and GHSA-56cj-wgg3-x943.
securitymediumCVE-2026-26311 and GHSA-84xm-r438-86px: HTTP
decode*blocking after downstream resetHTTP
decode*methods are blocked after a downstream reset. This release includes CVE-2026-26311 and GHSA-84xm-r438-86px.
Check if affected (2)
securityhighCVE-2026-26308 and GHSA-ghc4-35x6-crw5: multivalue header bypass fix in RBAC
Applies if you use the
rbacsubsystem.securitymediumCVE-2026-26330 and GHSA-c23c-rp3m-vpg3:
ratelimitresponse-phase limit crash fixApplies if you use the
ratelimitsubsystem.
A maintenance release focused on disclosed security fixes, with additional bug, dependency, and image updates. It also updates OAuth2 request handling, the Kafka test binary, and Docker base images.
Action needed (3)
securitymediumCVE-2026-26310 fix for scoped IPv6 address handling
Envoy fixes a crash in
getAddressWithPort()when it receives a scoped IPv6 address. The fix addresses CVE-2026-26310 and GHSA-3cw6-2j68-868p.securitymediumCVE-2026-26309 fix for
jsonstring terminator writesEnvoy fixes an off-by-one write that could corrupt the string null terminator in
json. The fix addresses CVE-2026-26309 and GHSA-56cj-wgg3-x943.securitymediumCVE-2026-26311 protection for
httpdecode methodsEnvoy blocks
decode*methods after a downstream reset inhttp. The fix addresses CVE-2026-26311 and GHSA-84xm-r438-86px.
Check if affected (2)
securityhighCVE-2026-26308 fix for
rbacmultivalue header bypassApplies if you use
rbac.securitymediumCVE-2026-26330 fix for
ratelimitresponse-phase crashesApplies if you use
ratelimit.
Envoy v1.35.9 is a maintenance release with security fixes in RBAC, network address handling, JSON processing, and HTTP downstream reset handling. It also includes an ordinary defect correction and an updated Docker base-image dependency.
Action needed (4)
securityhighCVE-2026-26308 and GHSA-ghc4-35x6-crw5, multivalue header bypass in RBAC
Envoy v1.35.9 fixes CVE-2026-26308 and GHSA-ghc4-35x6-crw5, addressing a multivalue header bypass in RBAC.
securitymediumCVE-2026-26310 and GHSA-3cw6-2j68-868p, scoped IPv6 address crash
Envoy v1.35.9 fixes CVE-2026-26310 and GHSA-3cw6-2j68-868p, preventing a crash in
getAddressWithPort()when it receives a scoped IPv6 address.securitymediumCVE-2026-26309 and GHSA-56cj-wgg3-x943, JSON null-terminator write
Envoy v1.35.9 fixes CVE-2026-26309 and GHSA-56cj-wgg3-x943, correcting an off-by-one write that could corrupt the string null terminator in JSON handling.
securitymediumCVE-2026-26311 and GHSA-84xm-r438-86px, HTTP decode methods after downstream reset
Envoy v1.35.9 fixes CVE-2026-26311 and GHSA-84xm-r438-86px, ensuring that
decode*methods are blocked after a downstream reset in HTTP handling.
A maintenance release with defect corrections, behavior changes, and a fix for credential leakage in pod events. It also updates the Go toolchain and adds a warning for concurrent container creation.
Action needed (1)
securityCredential leakage prevention in pod events
Credential leakage is prevented in pod events in this containerd release.
A release with disclosed security fixes in RBAC, network handling, JSON processing, and HTTP decoding, plus an OAuth2 correctness fix and updated Docker base images. Upgrading addresses the security vulnerabilities, while the other fixes require no operator action.
Action needed (4)
securityhighCVE-2026-26308 multivalue header bypass in
rbacCVE-2026-26308 (GHSA-ghc4-35x6-crw5) fixes a multivalue header bypass in
rbac. The fix ships in this Envoy release.securitymediumCVE-2026-26310 crash in
getAddressWithPort()CVE-2026-26310 (GHSA-3cw6-2j68-868p) fixes a crash in
getAddressWithPort()when it is called with a scoped IPv6 address. The fix ships in the Envoynetworkcode.securitymediumCVE-2026-26309 off-by-one write in
jsonprocessingCVE-2026-26309 (GHSA-56cj-wgg3-x943) fixes an off-by-one write that could corrupt the string null terminator. The fix ships in the Envoy
jsoncode.securitymediumCVE-2026-26311 blocking of
decode*methods after downstream resetCVE-2026-26311 (GHSA-84xm-r438-86px) ensures that
decode*methods are blocked after a downstream reset. The fix ships in the Envoyhttpcode.
A maintenance release with multiple Envoy and Istio security fixes covering request handling, authorization, authentication, and plugin image fetching. It also includes ordinary correctness fixes and adds configuration for authorized namespaces on debug endpoints.
Action needed (1)
securitymediumCVE-2026-26309 JSON off-by-one write fix
CVE-2026-26309 fixes an off-by-one write in JSON handling.
Check if affected (10)
securityhighCVE-2026-26308 multivalue header bypass fix
Applies if you use
RBAC.securityhighCVE-2026-31837 and GHSA-v75c-crr9-733c JWKS resolver authentication fix
Applies if you use
JWKS Resolver.securitymediumCVE-2026-26311 HTTP decode method restriction
Applies if you use
HTTP.- + 7 more on the release page
A security-focused maintenance release with fixes for disclosed Envoy and Istio vulnerabilities, including authentication, authorization, parsing, and crash defects. It also adds namespace authorization for debug endpoints and fixes lost InferencePool configurations during VirtualService merging.
Action needed (7)
securityhighCVE-2026-26308 multivalue header bypass fix in RBAC
CVE-2026-26308 fixes a multivalue header bypass in RBAC in Istio.
securityhighCVE-2026-31837 and GHSA-v75c-crr9-733c JWKS resolver authentication fix
CVE-2026-31837 and GHSA-v75c-crr9-733c fix a JWKS resolver failure that may allow authentication bypass using known default keys.
securitymediumCVE-2026-26311 HTTP decode method fix
CVE-2026-26311 blocks HTTP decode methods after a downstream reset in Istio.
securitymediumCVE-2026-26310 scoped IPv6 address crash fix
CVE-2026-26310 fixes a crash in
getAddressWithPort()when processing a scoped IPv6 address in Istio.securitymediumCVE-2026-26309 JSON off-by-one write fix
CVE-2026-26309 fixes a JSON off-by-one write in Istio.
securitymediumCVE-2026-26330 ratelimit response phase crash fix
CVE-2026-26330 fixes a crash in the ratelimit response phase in Istio.
securitymediumCVE-2026-31838 and GHSA-974c-2wxh-g4ww debug endpoint authorization fix
CVE-2026-31838 and GHSA-974c-2wxh-g4ww address cross-namespace proxy data access through debug endpoints.
Check if affected (3)
securityAuthentication for XDS debug endpoints on port 15010
Applies if you expose XDS debug endpoints.
securityBearer token realm URL validation for
WasmPluginimage fetchingApplies if you use
WasmPluginimage fetching.securityNamespace-based authorization for HTTP debug endpoints on port 15014
Applies if you expose HTTP debug endpoints.
A security-focused release with fixes across Envoy and Istio, including additional protections for debug endpoints, JWKS resolution, and WasmPlugin image fetching. The security fixes require an upgrade, while authorized namespace configuration for debug endpoints is optional.
Action needed (3)
securitymediumCVE-2026-26311 HTTP decode method correction
CVE-2026-26311 blocks HTTP decode methods after a downstream reset.
securitymediumCVE-2026-26310 scoped IPv6 address crash fix
CVE-2026-26310 fixes a crash in
getAddressWithPort()when handling a scoped IPv6 address.securitymediumCVE-2026-26309 JSON off-by-one write fix
CVE-2026-26309 fixes a JSON off-by-one write.
Check if affected (6)
securityhighCVE-2026-26308 multivalue header bypass fix
Applies if you use
RBAC.securityhighCVE-2026-31837 and GHSA-v75c-crr9-733c JWKS Resolver authentication fix
Applies if you use
JWKS Resolver.securitymediumCVE-2026-31838 and GHSA-974c-2wxh-g4ww debug endpoint access fix
Applies if you use
Debug Endpoints.- + 3 more on the release page