Flux v2.9.1 is a maintenance release focused on defect fixes, dependency and component updates, and a performance improvement. It includes changes across controller behavior and build and decryption paths, with no security advisories disclosed.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
OpenTelemetry v0.156.0 adds mdatagen and memory-limiter capabilities, changes generated configuration APIs, and corrects runtime and API defects. No security advisories or security-specific fixes are disclosed.
Source ↗OpenKruise v1.9.1 is a maintenance release focused on an operator-facing defect in Kubernetes server version parsing. The fix addresses a controller panic involving certain GKE and EKS version strings.
Source ↗k8gb v0.20.0 centers on ZoneDelegation-based DNS management, with TLSRoute and annotation support alongside changes to defaults and naming. The release also includes defect fixes and dependency updates, and no security advisories or vulnerabilities are identified.
Check if affected (4)
breakingThe
Bootstrapservice, removedApplies if your configuration uses the
Bootstrapservice.breakingThe
dynamicZonessetting, removedApplies if your configuration uses
dynamicZones.breakingThe
doFinalizedefault, set tofalseApplies if you use
doFinalizein ZoneDelegation finalization.- + 1 more on the release page
Lima v2.1.4 contains behavior fixes, FreeBSD template and general template updates, a nerdctl update from v2.3.3 to v2.3.4, and a change to the JSON network-list output. No security advisories or security-specific fixes are disclosed.
Source ↗OPA v1.18.2 is a patch release fixing a regression in opa fmt introduced in v1.18.0. The formatter again respects only newlines already present in source when formatting single-item arrays, objects, and sets.
This release adds the endpointslices/restricted virtual resource to RBAC. No further operator-facing details are specified.
CRI-O v1.35.5 includes an operator-facing correctness fix for container status ImageRef values after a CRI-O restart. It also updates CPU injection and gomaxprocs handling to account for workload partitioning and reduce potential Go scheduler throttling.
A feature and maintenance release that adds and changes capabilities across Core, PHP, Python, and Ruby, corrects runtime defects, and upgrades protobuf dependencies. The Python 1. package was removed from PyPI.
Check if affected (1)
breakinggRPC Python release
1., yanked from PyPI82. 0 Applies if you use
gRPC Python release 1..82. 0
A maintenance release with a forced internal PostgreSQL major-version upgrade, a redis to valkey cache backend replacement, dependency and component updates, and defect corrections. Token and blob-mount validation is hardened.
Action needed (1)
securityToken and blob-mount source validation
Blob-mount source projects are validated, and tokens without
iatare rejected.
Check if affected (2)
breakingThe bundled
PostgreSQLversion, upgradedApplies if you use
PostgreSQL.breakingThe cache backend, changed from
redistovalkeyApplies if you use
redis.
This release has no detailed changes available for display. The remaining release-note entry describes an operator-facing performance behavior update involving the gomaxprocs hook and CPU allocation.
CRI-O v1.34.10 is an operator-facing maintenance release with bug fixes in CPU allocation and container status reporting. It adjusts CPU handling to reduce scheduler throttling and preserves the ImageRef value across CRI-O restarts. No security advisories are identified.
A maintenance release with authentication and certificate-revocation enforcement fixes, Go toolchain and dependency updates, and a new v2 deprecation option. The security-related changes include fixes and dependency updates associated with the listed advisories.
Action needed (2)
securityhigh
go.dependencies, updated toopentelemetry. io/otel v1.43. 0 The
go.andopentelemetry. io/otel go.dependencies are updated fromopentelemetry. io/otel/sdk v1.to40. 0 v1.. The updates address CVE-2026-29181 and CVE-2026-39883.43. 0 securityhigh
golang., updated toorg/x/crypto v0.52. 0 The
golang.dependency is updated toorg/x/crypto v0.. The change is associated with CVE-2026-39828, CVE-2026-39835, CVE-2026-46597, and CVE-2026-46598.52. 0
Check if affected (1)
securityCRL enforcement bypass on the gRPC listener, fixed
Applies if
--listen-client-http-urlsis configured.
A maintenance release with server configuration, access control, authentication, validation, logging, and dependency updates. Deployments using the affected listener configuration or OpenTelemetry dependencies are directly concerned by the included fixes.
Action needed (1)
securityhighOpenTelemetry dependencies updated for CVE-2026-29181 and CVE-2026-39883
go.andopentelemetry. io/otel go.were updated fromopentelemetry. io/otel/sdk v1.to40. 0 v1.. The updates address CVE-2026-29181 and CVE-2026-39883.43. 0
Check if affected (1)
securityCRL enforcement with
--listen-client-http-urlsApplies if
--listen-client-http-urlsis configured.
A long-term support release with security-related dependency updates, PromQL changes, new APIs and configuration controls, and bug fixes. It also replaces a shipped license artifact and includes performance improvements.
Action needed (2)
securitycriticalThe
sanitize-htmldependency updateThe UI updates
sanitize-htmlto address a cross-site scripting vulnerability, identified as CVE-2026-44990.breakingThe third-party license artifact
Third-party npm dependency licenses are embedded in the Prometheus binary and served at
/assets/third-party-licenses.. This replaces thetxt npm_licenses.archive previously shipped in release tarballs and container images.tar. bz2
Check if affected (2)
securitymediumRedirect credential forwarding
Applies if you use scraping, remote read/write, alerting, or service discovery.
breakingPromQL duration-expression function names
Applies if you enable
experimental-duration-exprand usemin()andmax().
Longhorn v1.11.3 is a maintenance release with multiple correctness fixes and new metrics for LONGHORN_DISTRO. It requires Kubernetes v1.34 or later because the CSI external provisioner was upgraded to v6.3.0.
Istio 1.28.10 contains an operator-relevant correctness fix in the krt controller framework. The available release information does not include a standalone change item for this fix.
Source ↗Version v2.5.0 adds runtime and WIT/API capabilities and includes correctness and dependency updates. The release also enables wasip3 by default and includes a quinn-proto fix for RUSTSEC-2026-0185.
Action needed (1)
securityhighThe
quinn-protosecurity fixThe
quinn-protodependency fix ships in wasmCloud v2.5.0 and addresses RUSTSEC-2026-0185.
Check if affected (1)
breakingDefault
wasip3enablement withwasmtime46Applies if your workloads use
wasip3.
Release v1.14.0 adds tracing and observability capabilities and broadens ResolutionRequest resolution support. It also includes correctness fixes, a Go security-related update, and shipped dependency updates.
Action needed (1)
security
Go1.update26. 4 Gois updated to1.in v1.14.0 for CVE remediation.26. 4
Flux v2.9.0 removes two deprecated API versions and adds CLI and controller capabilities across several Flux resources. It also changes supported Kubernetes versions, corrects defects, and updates project and third-party dependencies.
Check if affected (1)
breakingRemoval of deprecated Flux API versions
Applies if your CRDs use the
image.ortoolkit. fluxcd. io/v1beta2 notification.APIs.toolkit. fluxcd. io/v1beta2
This release removes an orphan CRD, adds operator-facing capabilities and output changes, and corrects runtime, validation, reporting, and scan-processing defects. No security advisories or explicitly exploitable vulnerabilities are disclosed.
Check if affected (1)
breaking
SecurityExceptionCRD removalApplies if you use the
SecurityExceptionCRD.
This release updates the Alpine base image and fixes a Helm chart TLS certificate issue. The Helm fix applies to deployments that use a custom namespace, while the base image change addresses security concerns.
Action needed (1)
securityThe
alpinebase image, upgradedThe
alpinebase image is promoted fromalpine:3.to23. 4 alpine:3.to address security concerns.24. 1
Karmada v1.17.4 updates its Alpine base image to address security concerns. The release also fixes a Helm chart TLS certificate SAN mismatch when deploying to a custom namespace.
Action needed (1)
securityThe
alpinebase image, updated toalpine:3.24. 1 The
alpinebase image is updated fromalpine:3.to23. 4 alpine:3.to address security concerns. The update ships in Karmada v1.17.4.24. 1
Karmada v1.16.7 updates its Alpine base image for security concerns and includes a Helm chart fix for TLS certificate SANs in custom namespaces. The release affects deployments that use the updated image or the affected Helm chart configuration.
Action needed (1)
securityThe
alpinebase image, updatedThe base image
alpineis promoted fromalpine:3.to23. 4 alpine:3.to address security concerns.24. 1
A maintenance release with a security fix for unbounded reads in the Terraform remote configuration loader and a correctness fix for CUE imports in status details. It also adds repository ownership metadata.
Check if affected (1)
securityUnbounded read prevention in the Terraform remote configuration loader
Applies if you use the Terraform remote configuration loader.
This release includes a security correction for an unbounded-read denial-of-service condition in the Terraform remote configuration loader. The fix is backported to release-1. and concerns deployments that use this loader.
Check if affected (1)
security
Terraform remote configuration loaderDoS fix (GHSA-fmgp-q6jx-gg3x)Applies if you use the Terraform remote configuration loader.
This release contains an experimental authorization evaluation change and an IP address matching semantics change. The remaining updates are diagnostic or storage-internal and do not require operator action.
Source ↗A maintenance release with a dependency and toolchain update, broad defect corrections, and behavior improvements across authentication, routing, monitoring, clustering, and JetStream. It also removes JSONP monitoring callbacks and addresses MQTT and authorization-related connection and permission handling.
Check if affected (3)
security
Nats-Trace-Destpublish permission checks for leaf connectionsApplies if you use Leaf connections.
security
MQTTsubscribe deny rules on retained message and QoS replay pathsApplies if you use
MQTT.breakingThe
JSONPcallback support in monitoring endpoints, removedApplies if you use JSONP callback support.
A maintenance release with dependency updates, operational behavior changes, and correctness fixes across General, MQTT, Monitoring, and JetStream. It also removes JSONP callback support from monitoring endpoints.
Check if affected (1)
breakingThe
JSONPcallback support in monitoring endpoints, removedApplies if you use
JSONPcallback support.
OPA v1.18.1 corrects a memory leak introduced in OPA v1.17.0. No individual change entries are included here.
Source ↗This release adds operator-facing configuration and feature capabilities while updating supported Apache Kafka versions and related integrations. It also changes TLS file handling for KafkaBridge and KafkaMirrorMaker2 and renames entity-operator healthcheck ports, so those areas may require attention.
Check if affected (3)
breakingSupport for
Kafka 4.removed1. x Applies if you use
Kafka 4..1. x breakingPEM-based TLS files for
KafkaBridgeandKafkaMirrorMaker2Applies if you use
KafkaBridgeorKafkaMirrorMaker2with TLS authentication or a TLS truststore.breakingEntity-operator healthcheck port names
Applies if you use entity-operator healthcheck ports.
Volcano v1.14.3 is a bug-fix release for operator-relevant scheduling, resource accounting, pod metadata, status handling, and scheduler snapshots. The recorded release data contains no individual change entries to display.
Source ↗Version 26.6.4 is a security-focused Keycloak release with fixes for disclosed vulnerabilities. It also upgrades Quarkus to 3., an informational dependency change for operators.
Action needed (8)
securityhighCVE-2026-9099, group-admin escalation to realm-admin
Version 26.6.4 fixes the group-admin escalation to realm-admin identified as CVE-2026-9099 in Keycloak.
securityhighCVE-2026-9086, cross-site scripting via URI validation bypass
Version 26.6.4 fixes the cross-site scripting issue caused by a case-insensitive URI validation bypass identified as CVE-2026-9086 in Keycloak.
securityhighCVE-2026-9795, improper scope mapping enforcement
Version 26.6.4 fixes the privilege escalation caused by improper scope mapping enforcement identified as CVE-2026-9795 in Keycloak.
securityhighCVE-2026-9800, policy enforcer URI comparison
Version 26.6.4 fixes the authorization bypass caused by incorrect URI comparison in the Keycloak policy enforcer, identified as CVE-2026-9800.
securityhighCVE-2026-11800, JWT algorithm confusion authentication bypass
Version 26.6.4 fixes the JWT algorithm confusion authentication bypass identified as CVE-2026-11800 in Keycloak.
securitymediumCVE-2026-9083, arbitrary filesystem path probing
Version 26.6.4 fixes the information disclosure through arbitrary filesystem path probing identified as CVE-2026-9083 in Keycloak.
securitymediumCVE-2026-9705, disabled client takeover
Version 26.6.4 fixes the issue identified as CVE-2026-9705, which allowed disabled clients to be re-enabled and taken over through a registration access token in Keycloak.
securitymediumCVE-2026-9799, UMA permission ticket bypass
Version 26.6.4 fixes the unauthorized resource access caused by a UMA permission ticket bypass identified as CVE-2026-9799 in Keycloak.
This release primarily updates dependencies and base images, including the Ansible operator plugin version. No security advisories or explicitly described vulnerabilities are included.
Source ↗Backstage v1.52.1 is a maintenance release focused on operator-facing defect fixes. It addresses scheduler task state during trigger changes and a broken configuration schema in the Kubernetes React plugin.
Source ↗Version v0.13.1 contains a correctness fix, a configuration or behavior adjustment, and dependency and toolchain updates. No security advisories or operator actions are disclosed.
Source ↗A release with a breaking change to the outbound User-Agent value, along with restored automatic GOMAXPROCS handling and new automatic GOMEMLIMIT support. It also improves formatting and coverage behavior, corrects compiler and runtime defects, and updates dependencies.
Check if affected (1)
breakingThe
User-Agentheader formatApplies if you configure server-side log filters or WAF rules that exact-match the old string.
OpenCost v1.120.4 is a maintenance release with operator-facing fixes and updates to configuration, tooling, provider integrations, and runtime behavior. No security advisories or explicit security vulnerabilities are disclosed.
Source ↗cert-manager v1. changes permissions in the cert-manager-edit aggregate ClusterRole and updates the Go toolchain. Workflows that directly create or modify Challenge or Order resources may require explicit permissions after the release.
Action needed (2)
securityhigh
Gov1.with fixes for CVE-2026-27145, CVE-2026-42504, and CVE-2026-4250725. 11 Gois updated tov1.in cert-manager25. 11 v1.to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507.19. 6 security
Go1.dependency upgrade25. 10 Gois upgraded to1.as part of the dependency updates in cert-manager25. 10 v1..19. 6
Check if affected (1)
securityReduced
cert-manager-editpermissions forChallengeandOrdercreation and updatesApplies if you use the
cert-manager-editaggregate ClusterRole for workflows that create or modifyChallengeorOrderresources.
A security-focused patch release removes unsafe ACME permissions and includes fixes for identified CVEs. It also corrects Challenge garbage collection and updates Go dependencies.
Action needed (1)
securityhigh
Goupdated tov1.26. 4 Gois updated tov1.to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507.26. 4
Check if affected (1)
securityThe
cert-manager-editaggregate ClusterRole permissionsApplicability is not stated in the release notes.