This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+7 more
ReleasePort's take
Light signalTraefik v3.6.17 fixes CVE-2026-44774. Additional bugfixes address cross‑provider namespace handling for Kubernetes providers and CRD references.
Why it matters: Patch to v3.6.17 immediately to remediate CVE-2026-44774, which has a severity score of 50 (high).
Summary
AI summaryCVE-2026-44774 security vulnerability fixed.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
CVE-2026-44774 fixed (GHSA-96qj-4jj5-wcjc) CVE-2026-44774 fixed (GHSA-96qj-4jj5-wcjc) Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Bugfix | Medium |
Add CrossProviderNamespaces option for k8s/ingress, k8s/crd, k8s/gatewayapi Add CrossProviderNamespaces option for k8s/ingress, k8s/crd, k8s/gatewayapi Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Fix cross-provider ref check for Kubernetes CRD provider Fix cross-provider ref check for Kubernetes CRD provider Source: llm_adapter@2026-05-21 Confidence: high |
— |
Full changelog
Important: Please read the migration guide.
CVE fixed:
- CVE-2026-44774 (Advisory GHSA-96qj-4jj5-wcjc)
Bug fixes:
Security Fixes
- CVE-2026-44774 (GHSA-96qj-4jj5-wcjc) — security vulnerability fixed.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]