✓ No known CVEs patched
This release patches 5 known CVEs
Topics
cloudnative
grafana
logging
prometheus
Affected surfaces
deps
Summary
AI summaryUpdates Bug Fixes, release-3.6.x, and 3.6.13 across a mixed release.
Full changelog
3.6.13 (2026-07-23)
Bug Fixes
- ci: Fix zizmor findings for operator-images in Loki 3.6 (#22821) (050f742)
- ci: Helm CI warning fix (#22606) (4bc2586)
- security/CRITICAL/clients/cmd/fluentd/docker: Update dependency fluentd to v1.19.3 [SECURITY] (release-3.6.x) (#22694) (692f2b1)
- security/HIGH/: Bump Go to 1.26.5 to address CVE-2026-39822 and CVE-2026-42505 [SECURITY] (#23398) (fc478e1)
- security/HIGH/pkg/push: Update module google.golang.org/grpc to v1.82.1 [SECURITY] (70f75b7)
- security/HIGH/: Update golang.org/x/net, golang.org/x/text and google.golang.org/grpc [SECURITY] (70f75b7)
- security/UNKNOWN/cmd/chunks-inspect: Update go toolchain directive to v1.25.12 [SECURITY] (release-3.6.x) (#23131) (b327439)
- security/UNKNOWN/pkg/push: Update module golang.org/x/net to v0.56.0 [SECURITY] (70f75b7)
- security/UNKNOWN/pkg/push: Update module golang.org/x/text to v0.39.0 [SECURITY] (70f75b7)
- security/UNKNOWN/: Update module github.com/containerd/containerd/v2 to v2.0.10 [SECURITY] (release-3.6.x) (#22479) (697bd83)
- security: Backport security updates to release-3.6.x (#23403) (70f75b7)
- Update objstore to include fix for GCS Exists (#23381) (87383d8)
Security Fixes
- Bump Go to 1.26.5 — addresses CVE-2026-39822 and CVE-2026-42505
- Update module google.golang.org/grpc to v1.82.1 [SECURITY]
- Update modules golang.org/x/net, golang.org/x/text and grpc [SECURITY]
- Backport security updates to release‑3.6.x
- CVE-2026-42505
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]