Skip to content

LLMKube

v0.9.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai apple-silicon autoscaling edge-computing gguf gpu
+12 more
self-hosted inference kubernetes llama-cpp llm local-llm metal mlx multi-gpu nvidia tgi vllm

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Updates Bug Fixes, ⚠ BREAKING CHANGES, and GHSA-jw3m-8q7m-f35r across a mixed release.

Full changelog

0.9.0 (2026-07-05)

⚠ BREAKING CHANGES

  • security: gate local/hostPath model sources + block controller SSRF (GHSA-jw3m-8q7m-f35r) (#981)

Features

  • foreman: use the reviewer's summary as the opened-PR body (#975) (e031ff5)

Bug Fixes

  • foreman: populate FleetNode.Status.CurrentTask so the scheduler spreads work (#978) (d731a90)
  • foreman: reap orphaned Draining FleetNodes so they stop leaking (#980) (241ac4a)
  • runtime: bind inference servers to :: for IPv6-only clusters (#973) (398d5c1)
  • security: gate local/hostPath model sources + block controller SSRF (GHSA-jw3m-8q7m-f35r) (#981) (ec2647f)

Breaking Changes

  • Removal of unrestricted access to local/hostPath model sources; now gated and blocked for SSRF (GHSA-jw3m-8q7m-f35r).

Security Fixes

  • GHSA-jw3m-8q7m-f35r — gate local/hostPath model sources and block controller SSRF.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track LLMKube

Get notified when new releases ship.

Sign up free

About LLMKube

Kubernetes operator for llama.cpp-native LLM inference with GPU scheduling, Apple Silicon Metal support, and OpenAI-compatible API.

All releases →

Related context

Earlier breaking changes

  • v0.8.1 foreman: requestTimeoutSeconds now sets loop-wide budget, default changes from 600 to 3600.

Beta — feedback welcome: [email protected]