Skip to content

loki

v3.7.4 Security

This release includes 5 security fixes for security teams reviewing exposed deployments.

Published 2d Logging
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 5 known CVEs

Topics

cloudnative grafana logging prometheus

Affected surfaces

deps

Summary

AI summary

Updates Bug Fixes, release-3.7.x, and 3.7.4 across a mixed release.

Full changelog

3.7.4 (2026-07-22)

Bug Fixes

  • ci: Fix zizmor findings for operator-images in Loki 3.7 (#22820) (abc1186)
  • ci: Helm CI warning fix (#22605) (7389428)
  • ci: Re-enable docker plugin publishing (#22818) (28f44a8)
  • compactor: Fix delete request when using Thanos objstore client with filesystem backend [release-3.7.x] (#22811) (dd6fdb5)
  • deps: Update module charm.land/bubbletea/v2 to v2.0.7 (release-3.7.x) (#22768) (e11f935)
  • deps: Update module charm.land/lipgloss/v2 to v2.0.4 (release-3.7.x) (#22769) (10213c2)
  • deps: Update module github.com/aws/aws-sdk-go-v2/credentials to v1.19.24 (release-3.7.x) (#22776) (3daf198)
  • deps: Update module github.com/aws/smithy-go to v1.27.3 (release-3.7.x) (#22795) (1f6a191)
  • deps: Update module github.com/baidubce/bce-sdk-go to v0.9.270 (release-3.7.x) (#22783) (103ccd8)
  • deps: Update module github.com/coder/quartz to v0.3.1 (release-3.7.x) (#22784) (3509e31)
  • deps: Update module github.com/IBM/ibm-cos-sdk-go to v1.14.1 (release-3.7.x) (#22785) (d0abe72)
  • deps: Update module github.com/klauspost/compress to v1.18.6 (release-3.7.x) (#22797) (327da7c)
  • deps: Update module github.com/pierrec/lz4/v4 to v4.1.27 (release-3.7.x) (#22798) (6b3297f)
  • deps: Update module github.com/shirou/gopsutil/v4 to v4.26.5 (release-3.7.x) (#22800) (cb7f17d)
  • security/CRITICAL/clients/cmd/fluentd/docker: Update dependency fluentd to v1.19.3 [SECURITY] (release-3.7.x) (#22693) (6d8f1b5)
  • security/HIGH/: Bump Go to 1.26.5 to address CVE-2026-39822 and CVE-2026-42505 [SECURITY] (#23393) (b318f28)
  • security/HIGH/: Update module github.com/apache/thrift to v0.24.0 [SECURITY] (release-3.7.x) (#22767) (36eb5f7)
  • security/UNKNOWN/pkg/push: Update module golang.org/x/net to v0.55.0 [SECURITY] (release-3.7.x) (#22200) (dd7a124)
  • security/UNKNOWN/: Update module github.com/containerd/containerd/v2 to v2.0.10 [SECURITY] (release-3.7.x) (#22478) (6fa6165)
  • storage: Fix index filename issue with legacy S3 client and chunk_delimiter (#23165) (0eca83c)

Security Fixes

  • Bump Go to 1.26.5 addressing CVE-2026-39822 and CVE-2026-42505
  • Update fluentd dependency to v1.19.3 (SECURITY)
  • Update Apache Thrift module to v0.24.0 (SECURITY)
  • Update containerd/v2 module to v2.0.10 (SECURITY)
  • CVE-2026-42505

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track loki

Get notified when new releases ship.

Sign up free

About loki

Like Prometheus, but for logs.

All releases →

Beta — feedback welcome: [email protected]