This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+3 more
ReleasePort's take
Moderate signalVersion v1.9.1 patches CVE-2026-35469 and resolves several cross‑component bugs.
Why it matters: CVE-2026-35469 has a severity score of 95; applying this release mitigates the vulnerability immediately.
Summary
AI summarySecurity fix for CVE-2026-35469 and multiple bug fixes across Fix, Chore, and CI modules.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Addresses CVE-2026-35469 by cherry-picking fix from #4814. Addresses CVE-2026-35469 by cherry-picking fix from #4814. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Dependency | Low |
Updates google.golang.org/grpc dependency, fixing issue #4667. Updates google.golang.org/grpc dependency, fixing issue #4667. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Removes readinessProbe on rollout install to prevent false positives. Removes readinessProbe on rollout install to prevent false positives. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Creates isolated logger for redactor to avoid log contamination. Creates isolated logger for redactor to avoid log contamination. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Honors stderrthreshold when logtostderr is enabled in the controller. Honors stderrthreshold when logtostderr is enabled in the controller. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Guards null chartValue in dashboard metric chart tooltip, fixing UI glitch. Guards null chartValue in dashboard metric chart tooltip, fixing UI glitch. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Ensures early SetWeight runs after checkReplicasAvailable in traffic routing. Ensures early SetWeight runs after checkReplicasAvailable in traffic routing. Source: llm_adapter@2026-07-17 Confidence: high |
— |
Full changelog
v1.9.1 (2026-07-06)
Minor security release to address CVE-2026-35469
Chore
- Address CVE-2026-35469 (cherry-pick #4814 for 1.9) (#4824)
- deps: update google.golang.org/grpc. Fixes #4667 (#4686)
Ci
Fix
- remove readinessProbe on rollout install (#4704)
- create isolated logger for redactor (#4703)
- controller: honor stderrthreshold when logtostderr is enabled (#4673)
- dashboard: guard null chartValue in metric chart tooltip. Fixes #4743 (#4744)
- deps: restore go 1.24.9 on release-1.9 after bad grpc cherry-pick
- trafficrouting: ensure early SetWeight runs after checkReplicasAvailable (#4639)
Security Fixes
- CVE-2026-35469 — addressed via cherry-pick of issue #4814
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]