# Volcano v1.15.2

> Orchestration & Management · 2026-08-29

A security-focused maintenance release fixes a scheduler denial-of-service vulnerability in Dynamic Resource Allocation. It also contains corrections for scheduling and workload-management defects.

## Check if affected
- **[security]** `GHSA-j38h-7pfq-cxmw` scheduler denial-of-service vulnerability
  - Applies if you use `Dynamic Resource Allocation`.
  - A vulnerability in Volcano's `Dynamic Resource Allocation` capacity accounting could let an authenticated tenant exhaust scheduler CPU time with tenant-controlled device or task counts. The fix uses constant-time capacity aggregation with safer validation and overflow handling.

## Other recorded changes
- 4 (defect_corrected 4)

[Full analysis](https://ratatosk.io/en/releases/volcano/v1.15.2)

[Original release notes](https://github.com/volcano-sh/volcano/releases/tag/v1.15.2)
