|
1 | 1 | 18 Jun 2026 |
2 | 2 |
|
3 | | -#### Headline feature 1 |
4 | | - |
5 | | -#### Headline feature 2 |
6 | | - |
7 | 3 | #### Bug fixes |
8 | 4 |
|
9 | | -#### Other changes |
10 | | - |
11 | 5 | - calico/node now refreshes the CNI plugin's kubeconfig immediately when the pod's projected ServiceAccount token is rotated, closing a 6-12h window where an externally-invalidated token could cause CNI ADD to fail with "Unauthorized" until the calico-node pod was restarted. [calico 12941](https://github.com/projectcalico/calico/pull/12941) (@skoryk-oleksandr) |
12 | | -- NONE [calico 12939](https://github.com/projectcalico/calico/pull/12939) (@lucastigera) |
13 | | -- Upgrade bundled Envoy Gateway to v1.8.0 (adds ListenerSet support) and bump bundled envoy-proxy, envoy-ratelimit, and node-driver-registrar images. [calico 12933](https://github.com/projectcalico/calico/pull/12933) (@lucastigera) |
14 | | -- Updates LoadBalancer controller to not run when not explicitly configured as part of ENABLED_CONTROLLERS [calico 12932](https://github.com/projectcalico/calico/pull/12932) (@MichalFupso) |
15 | 6 | - Fix SNAT being skipped for traffic destined to LoadBalancer-only IPPools by excluding them from the all-ipam-pools ipset. [calico 12857](https://github.com/projectcalico/calico/pull/12857) (@defo89) |
16 | 7 | - Fix calico-kube-controllers IPAM GC controller getting stuck when cleaning up nodes during rapid scale-down. [calico 12746](https://github.com/projectcalico/calico/pull/12746) (@haojiwu) |
17 | 8 | - ebpf - Fix kube-proxy losing the NodePort externalTrafficPolicy=Local route-fixup trigger after a syncer swap, which could cause stale NAT entries on remote backends. [calico 12744](https://github.com/projectcalico/calico/pull/12744) (@tomastigera) |
18 | 9 | - Fixes nft binary segfaults in calico/node when newer nftables is in use elsewhere on the host. [calico 12714](https://github.com/projectcalico/calico/pull/12714) (@caseydavenport) |
19 | 10 | - ebpf - Fix transient NodePort connection failures when Felix restarts on a node receiving external NodePort traffic. [calico 12693](https://github.com/projectcalico/calico/pull/12693) (@tomastigera) |
20 | 11 | - Fixes a Felix panic that could occur when an IP set selector matched both a NetworkSet CIDR and workload IPs contained within it, with nftables as the active dataplane. [calico 12672](https://github.com/projectcalico/calico/pull/12672) (@caseydavenport) |
21 | | -- kube-controllers, goldmane: use default secure pprof server (localhost only). Use `kubectl port-forward` for remote access. [calico 12634](https://github.com/projectcalico/calico/pull/12634) (@Behnam-Shobiri) |
22 | | -- Sanitize log output [calico 12606](https://github.com/projectcalico/calico/pull/12606) (@Behnam-Shobiri) |
23 | 12 | - Typha now rejects oversized inbound client gob frames before reading them, preventing a potential denial-of-service caused by excessive memory allocation. [calico 12591](https://github.com/projectcalico/calico/pull/12591) (@Behnam-Shobiri) |
24 | 13 | - Fix LoadBalancer IPAM race on kube-controllers startup that could assign multiple addresses to a Service. [calico 12569](https://github.com/projectcalico/calico/pull/12569) (@MichalFupso) |
| 14 | +- Fixed a Felix eBPF cleanup race condition that could cause a nil-pointer panic when an interface disappeared during TC qdisc cleanup. [calico 12481](https://github.com/projectcalico/calico/pull/12481) (@Behnam-Shobiri) |
| 15 | +- Fix nftables segfault on systems with newer nft versions (Debian Trixie, Fedora 42+) by bumping knftables to v0.0.21. [calico 12470](https://github.com/projectcalico/calico/pull/12470) (@caseydavenport) |
| 16 | + |
| 17 | +#### Other changes |
| 18 | + |
| 19 | +- Upgrade bundled Envoy Gateway to v1.8.0 (adds ListenerSet support) and bump bundled envoy-proxy, envoy-ratelimit, and node-driver-registrar images. [calico 12933](https://github.com/projectcalico/calico/pull/12933) (@lucastigera) |
| 20 | +- Updates LoadBalancer controller to not run when not explicitly configured as part of ENABLED_CONTROLLERS [calico 12932](https://github.com/projectcalico/calico/pull/12932) (@MichalFupso) |
| 21 | +- kube-controllers, goldmane: use default secure pprof server (localhost only). Use `kubectl port-forward` for remote access. [calico 12634](https://github.com/projectcalico/calico/pull/12634) (@Behnam-Shobiri) |
| 22 | +- Sanitize log output [calico 12606](https://github.com/projectcalico/calico/pull/12606) (@Behnam-Shobiri) |
25 | 23 | - Sanitize calicoctl log output [calico 12537](https://github.com/projectcalico/calico/pull/12537) (@Behnam-Shobiri) |
26 | 24 | - app-policy (Dikastes): normalize HTTP request-target before evaluating Application Layer Policy path rules, and reject shapes whose resolved form depends on upstream-specific decoding. Request paths are now RFC 3986 / RFC 7230 normalized (decode percent-escapes once, resolve dot-segments and repeated slashes, fold backslashes, strip matrix parameters per segment) and prefix matches are anchored to path-segment boundaries. Paths whose decoded form still contains percent-encoded path separators (%2e / %2f / %5c), or contains a null byte, are rejected. [calico 12533](https://github.com/projectcalico/calico/pull/12533) (@electricjesus) |
27 | 25 | - Sanitize CNI plugin log output. [calico 12527](https://github.com/projectcalico/calico/pull/12527) (@Behnam-Shobiri) |
28 | | -- Fixed a Felix eBPF cleanup race condition that could cause a nil-pointer panic when an interface disappeared during TC qdisc cleanup. [calico 12481](https://github.com/projectcalico/calico/pull/12481) (@Behnam-Shobiri) |
29 | | -- Fix nftables segfault on systems with newer nft versions (Debian Trixie, Fedora 42+) by bumping knftables to v0.0.21. [calico 12470](https://github.com/projectcalico/calico/pull/12470) (@caseydavenport) |
30 | 26 | - Use cryptographically secure random number generator for X.509 certificate serial numbers. [calico 12467](https://github.com/projectcalico/calico/pull/12467) (@Behnam-Shobiri) |
0 commit comments