This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+7 more
Affected surfaces
Summary
AI summaryFixed TLS router handling when multiple routers share the same host but use different TLS options on distinct entry points.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Bump go-proxyproto dependency to v0.12.0. Bump go-proxyproto dependency to v0.12.0. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Reject cross-provider references with backendRefs.namespace in k8s/gatewayapi. Reject cross-provider references with backendRefs.namespace in k8s/gatewayapi. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Fix routers with same host but different TLS options on separate entryPoints. Fix routers with same host but different TLS options on separate entryPoints. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Fix SNICheck for routers lacking host definitions. Fix SNICheck for routers lacking host definitions. Source: llm_adapter@2026-06-10 Confidence: high |
— |
Full changelog
Bug fixes:
- [k8s/gatewayapi] Reject cross-provider references with backendRefs.namespace (#13322 @youkoulayley)
- [server] Bump to github.com/pires/go-proxyproto v0.12.0 (#13313 @timschumi)
- [tls] Fix routers with same host, different tlsoptions on different entryPoint (#13329 @juliens)
- [tls] Fix snicheck for routers with no hosts (#13333 @rtribotte)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]