This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+8 more
Affected surfaces
Summary
AI summaryFixed regression that broke API authentication with certain HTTP client libraries.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Adds support for OpenSSL 4.0, enabling compatibility with newer versions. Adds support for OpenSSL 4.0, enabling compatibility with newer versions. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Deprecation | Low |
Removes Amazon Linux 2 from documentation after its end‑of‑life. Removes Amazon Linux 2 from documentation after its end‑of‑life. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Fixes regression breaking API authentication for clients sending Basic Auth credentials after server challenge. Fixes regression breaking API authentication for clients sending Basic Auth credentials after server challenge. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Prevents indefinite hanging when connecting to endpoints, allowing further connection attempts without restarting Icinga 2. Prevents indefinite hanging when connecting to endpoints, allowing further connection attempts without restarting Icinga 2. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Tracks objects deleted at runtime to avoid erroneous recreation during replay log processing. Tracks objects deleted at runtime to avoid erroneous recreation during replay log processing. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Improves locking of performance data arrays to prevent possible deadlocks. Improves locking of performance data arrays to prevent possible deadlocks. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Reduces high response latency for API requests targeting non‑existent hosts or services. Reduces high response latency for API requests targeting non‑existent hosts or services. Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
This release contains a number of fixes for various smaller but annoying bugs, including one regression regarding API authentication with certain HTTP client libraries. It also ensures that Icinga 2 is compatible with newer OpenSSL versions.
Bugfixes
- Track objects deleted at runtime to avoid erroneous recreation when processing the replay log (#10933)
- Ensure that connecting to endpoints can no longer hang indefinitely, which had stopped it from initiating further connection attempts until Icinga 2 was restarted (#10929)
- Fix a regression introduced with v2.16.0, that broke API authentication for clients that only send HTTP Basic Auth credentials after the server requested them (#10927)
- Improve locking of performance data arrays to prevent possible deadlocks (#10930)
- Fix high response latency with multiple API requests targeting non-existent hosts or services (#10928)
Enhancements and Documentation
- Add support for OpenSSL 4.0 (#10934)
- Remove Amazon Linux 2 from the documentation after it has reached its end of life (#10935)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Icinga
The core of our monitoring platform with a powerful configuration language and REST API.
Related context
Related tools
Beta — feedback welcome: [email protected]