istio(1.29.7): Critical Security Hardening, Ambient Mesh Stability, and Core Fixes

📋 Recommended Actions ⚠️ Action Required Immediate upgrade recommended to patch critical security vulnerabilities and ensure robust ambient mesh operation. 📝 Summary This release, Istio 1.29.7, delivers essential security fixes and significant stability enhancements across the mesh. We’ve tackled multiple vulnerabilities, including an EnvoyFilter regex denial-of-service vector and an SSRF vulnerability in JWKS URI fetching. Critical functional security fixes ensure BackendTLSPolicy now fails closed when CA references are unresolved and close a Gateway API TLS certificateRef existence oracle. For Ambient Mesh users, stability and performance are greatly improved. We’ve resolved issues where ingress gateways bypassed waypoints in multi-cluster setups and prevented hostNetwork pods from erroneous enrollment. Resource management gets a boost with fixes for istio-cni file descriptor leaks and optimized policy scanning. Furthermore, WDS reconnects are now version-aware, significantly reducing traffic during ztunnel reconnections. Core platform reliability also sees important updates, like a fix for istiod leader election goroutine leaks and improved Gateway API port name disambiguation. Upgrade today to fortify your mesh against potential exploits and benefit from a more resilient and efficient Istio experience. ...

August 27, 2026 · Daniel Grenemark

cert-manager(v1.20.2): Critical Security Patches and Core Dependency Updates

📋 Recommended Actions ⚠️ Action Required Immediate patching is required. This release addresses critical security vulnerabilities in core dependencies like go-jose and the Go runtime. Upgrade promptly to protect your cert-manager deployments. 📝 Summary cert-manager v1.20.2 lands with crucial security fixes and essential dependency updates. This patch release tackles CVE-2024-28180, a critical authentication bypass in the underlying go-jose library. Furthermore, it incorporates Go runtime v1.26.2, which includes fixes for high-severity issues like CVE-2024-24791 (TLS DoS) and CVE-2024-24792 (HTTP/2 memory exhaustion). These updates are vital for maintaining the integrity and availability of your certificate management infrastructure. You’ll also find updated OpenTelemetry libraries, improving observability foundations, and a minor Helm chart indentation fix. Upgrade quickly to secure your clusters. ...

April 11, 2026 · Daniel Grenemark

cert-manager(v1.19.4): Critical Security Patches and Essential Dependency Updates

📋 Recommended Actions ⚠️ Action Required Immediate patching is highly recommended to address the OpenTelemetry security vulnerability (GO-2026-4394) and to benefit from the latest Go runtime and base image security updates. 📝 Summary Cert-manager v1.19.4 brings crucial security and maintenance updates, bolstering the reliability of your certificate management. This release addresses a medium-severity OpenTelemetry vulnerability (GO-2026-4394) related to sensitive data exposure in HTTP headers, making an upgrade vital for enhanced security posture. We’ve also updated the Go runtime to version 1.25.7, incorporating the latest performance improvements and bug fixes. Furthermore, all base images have been refreshed to Debian 12, ensuring cert-manager components run on the most current and secure foundations. These updates are essential for maintaining a stable and secure Kubernetes environment. Upgrade soon to protect your clusters and leverage these core improvements. ...

February 24, 2026 · Daniel Grenemark