구성 범위와 LLMInferenceService 기능이 확장된 운영자 릴리스로, 차트 및 의존성 업데이트와 동작 변경, 제거, 결함 수정이 함께 포함됩니다. 설명된 보안 수정 사항도 운영 환경에서 검토하고 적용할 내용입니다.
조치 필요 (13)
securitycritical
h11잘못된 본문 처리 수정형식이 잘못된 본문을 허용하던
h11문제인 CVE-2025-43859를 수정했습니다.securityhigh
starlette버전 고정starlette버전을0.로 고정해 CVE-2025-62727을 수정했습니다.49. 1 securityhigh
lightgbm버전 업데이트lightgbm버전을4.으로 업데이트해 CVE-2024-43598을 수정했습니다.6. 0 securityhigh압축 해제 링크 수 제한 문제 수정
압축 해제 과정에서 링크 수가 제한 없이 늘어나는 CVE-2025-66418 문제를 수정했습니다.
securityhigh
expr-lang/expr업데이트expr-lang/expr를v1.로 업데이트해 CVE-2025-68156을 수정했습니다.17. 7 securityhigh
cryptographysubgroup attack 수정cryptography의 subgroup attack과 관련된 CVE-2026-26007을 수정했습니다.securityhigh
python-multipart임의 파일 쓰기 수정python-multipart의 임의 파일 쓰기 문제인 CVE-2026-24486을 수정했습니다.securitymedium여러 CVE 수정
CVE-2025-22872, CVE-2025-47914, CVE-2025-58181을 수정했습니다.
security
https.경로 탐색 방지go https.에서 경로 탐색이 발생하지 않도록 수정했습니다.go security여러 CVE 관련 문제 수정
여러 CVE 관련 문제를 수정했습니다.
security
AIOHTTP자동 압축 해제 문제 수정AIOHTTP의 HTTP 파서에서auto_decompress기능을 악용한 zip bomb 문제를 수정했습니다.security
extractTarFiles경로 탐색 수정extractTarFiles에서 발생하는 경로 탐색 취약점을 수정했습니다.breaking
minio를seaweedfs로 교체minio를seaweedfs로 교체했습니다.
영향 확인 (6)
breaking
inferenceserviceCRD cert-manager 주석 제거inferenceserviceCRD를 사용하는 경우에 해당합니다.inferenceserviceCRD에서 cert-manager 주석을 제거했습니다.breakingPython 3.9 지원 제거
Python 3.을 실행하는 경우에 해당합니다.9 Python 3.9 지원을 제거했습니다.
breaking
--disable-log-requests플래그 제거--disable-log-requests를 설정하는 경우에 해당합니다.사용 중단된
--disable-log-requests플래그를 제거했습니다.- 릴리스 페이지에 3건 더