Zum Inhalt springen

cert-manager Release Notes

30 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge cert-manager, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.20.4: Sicherheitsupdates und ingress-shim-Fix

cert-manager v1.20.4 aktualisiert Go und mehrere Abhängigkeiten zur Behebung gemeldeter Sicherheitslücken und behebt einen Fehler, bei dem ingress-shim das applyset-Label von zwischengespeicherten Ingress- und Gateway-Objekten entfernte.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release updates Go and several dependencies to fix reported security vulnerabilities, and fixes a bug where ingress-shim removed the applyset label from cached Ingress and Gateway objects.

All users should upgrade.

[!NOTE] Security scanners still report three golang.org/x/crypto findings. None of them affects cert-manager and we do not plan to fix them in the 1.20 line.

  • CVE-2026-56855 and CVE-2026-78662 are deadlocks in the golang.org/x/crypto/ssh connection multiplexer, triggered by a malicious SSH peer after a connection is established. cert-manager never opens an SSH connection. Only the controller links the ssh package, through vcert, which uses it to format a public key. The fix, golang.org/x/crypto v0.56.0, requires Go language version 1.26, which we will not adopt in a patch release. govulncheck confirms the vulnerable functions are not called.
  • GO-2026-5932 marks golang.org/x/crypto/openpgp as unmaintained. cert-manager does not import that package and there is no fixed version.

cert-manager 1.21 already uses golang.org/x/crypto v0.56.0, so upgrade to 1.21 if you need a clean scan.

Changes by Kind

Bug or Regression …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.21.2: Panics, Races und Sicherheitslücken behoben

cert-manager v1.21.2 behebt Panics im Controller und Webhook, Data Races, ACME-Renewal- und HTTP-01-Solver-Fehler sowie einen dnsNames-Fehler bei Gateway API, verhindert, dass ACME- und Vault-Issuer unvertrauenswürdige HTTP-Antworten in Status und Events übernehmen, schränkt die Nutzung von AWS-Umgebungsanmeldedaten bei namespaced Vault Issuers ein und aktualisiert Go und Abhängigkeiten gegen Sicherheitslücken.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.21.2 fixes controller and webhook panics, data races, ACME renewal and HTTP-01 solver bugs, and a Gateway API dnsNames bug. It stops the ACME and Vault issuers copying untrusted HTTP response bodies into status conditions and Events, and tightens ambient AWS credential use for namespaced Vault Issuers. It also updates Go and several dependencies to fix reported security vulnerabilities.

All users should upgrade.

Changes by Kind

Bug or Regression

  • ACME Issuer response bodies are no longer reflected into Issuer status conditions or Kubernetes Events. Only ACME problem documents are surfaced (bounded in length); other responses are reported by HTTP status code alone, with the full error available in the controller logs. (#9239, @FelixPhipps)
  • Cap ACME server response bodies at 16 MiB to guard against unbounded-body denial-of-service. (#9222, @FelixPhipps)
  • De-duplicate dnsNames when multiple Gateway/ListenerSet listeners share a Secret (#9234, @speer)
  • Fix certificate renewal windows using February 29 cron schedules across non-leap century years. (#9240, @wieghx) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.21.1: Controller-Panic bei Renewal Disabled behoben

cert-manager v1.21.1 behebt einen Controller-Panic bei Certificates mit spec.renewal.policy: Disabled, Log-Spam und verlorene Secret-Informer-Events aus 1.21.0, hängende Issuer/ClusterIssuer bei Ready=False (InvalidSolver) sowie das Gateway-API-Beispiel in den Helm-Chart-Werten und aktualisiert Abhängigkeiten gegen Sicherheitslücken.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.21.1 fixes a controller panic for Certificates with spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck at Ready=False (InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.

All users should upgrade.

Changes by Kind

Bug or Regression

  • Avoid controller panic if a Certificate sets spec.renewal.policy=Disabled (#9038, @sklirg)
  • Fix Issuer/ClusterIssuer stuck at Ready=False/InvalidSolver after a missing ACME DNS-01 solver Secret is created (#9083, @SebTardif)
  • Fix log spam and dropped Secret informer events for non-cert-manager Secrets, caused by a generics regression introduced in 1.21.0. (#9037, @wallrj-cyberark)
  • Fixed the commented Gateway API config example in the Helm chart values to use gatewayAPI.enabled instead of the invalid gatewayAPI.enable. (#9012, @mateenali66)

Other (Cleanup or Flake)

  • Bump golang.org/x/text to v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark)
  • Bump google.golang.org/grpc to v1.82.1 to fix a reported security vulnerability (#9063) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.21.0: ACME ARI, Vault-AWS-IAM und Breaking Changes

cert-manager 1.21.0 bringt ACME Renewal Information (ARI), AWS-IAM-Authentifizierung für den Vault-Issuer, Sicherheitshärtungen und Verbesserungen bei Gateway API und cainjector, enthält drei Breaking Changes bei Helm-Chart-RBAC und Metrics-Werten und hat die bekannte Einschränkung, dass der Controller bei renewal.policy: Disabled abstürzt.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager 1.21 brings ACME Renewal Information (ARI) support, AWS IAM authentication for the Vault issuer, several security hardening changes, and continued improvements to Gateway API integration and cainjector. There are three breaking changes related to Helm chart RBAC and metrics values — review them carefully before upgrading.

Known Issues

  • Controller crash-loops when a Certificate sets renewal.policy: Disabled: the new Certificate renewal policies feature (#8258) causes a nil pointer dereference panic in the trigger controller whenever a Certificate's spec.renewal.policy is set to Disabled — pki.RenewalTime() returns (nil, nil) for that policy, but the caller unconditionally dereferences the result. This crashes the controller process (crash-loop) for any cluster with such a Certificate. Workaround: do not set renewal.policy: Disabled on any Certificate until this is fixed; remove the field (or set a different policy) from any Certificate that already has it, and restart the controller if it is currently crash-looping. See #9031 for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.21.0-beta.0

Die Vorabversion cert-manager 1.21.0-beta.0 (nur zum Testen) ergänzt unter anderem eine Option für maximales Retry-Backoff bei CertificateRequests, ARI-Unterstützung über das Feature Gate ACMEUseARI, AWS-IAM-Authentifizierung für den Vault Issuer und konfigurierbaren runtimeClassName.

[!NOTE] ⚠️ This is a pre-release. For testing only!

For full release notes including breaking changes, upgrade notes, major themes and community credits, see the v1.21 release notes.

Changes since v1.21.0-alpha.1

Feature

  • Add certificateRequestMaximumBackoffDuration controller configuration option to cap retry backoff time for failed CertificateRequests. Configurable via config file, --certificate-request-maximum-backoff-duration CLI flag, or Helm value config.certificateRequestMaximumBackoffDuration. Defaults to 32 hours for backward compatibility. (#8893, @lunarwhite)
  • Add an optional waitInsteadOfSelfCheck field to ACME HTTP01 and DNS01 solvers so cert-manager can skip its own self-check and ask the ACME server to validate after a configured wait. (#8858, @wallrj)
  • Add configurable runtimeClassName support for cert-manager components and ACME HTTP01 solver pods. (#8791, @jsoref)
  • Added ARI support through the ACMEUseARI feature gate. (#8798, @hjoshi123)
  • Added AWS IAM authentication support for Vault issuer, including IRSA (IAM Roles for Service Accounts) and ambient credentials (EC2/ECS). (#8422, @bitloi)
  • Adds support for the Modern2026 go-pkcs12 profile and FIPS 140-3. (#8841, @seanorama) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.20.3 schließt Sicherheitslücke

cert-manager 1.20.3 behebt eine Sicherheitslücke (HIGH), bei der die ClusterRole cert-manager-edit Namespace-Nutzern das direkte Erstellen von ACME-Challenge- und Order-Ressourcen erlaubte, entfernt zudem die Issuer-Owner-Reference von Challenges und aktualisiert Go; ein Upgrade wird allen Nutzern empfohlen.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release fixes a security issue (GHSA-8rvj-mm4h-c258, HIGH) where the default cert-manager-edit aggregate ClusterRole granted namespace users permission to create ACME Challenge and Order resources directly. A user who could create a Challenge referencing a ClusterIssuer could supply attacker-controlled solver configuration while cert-manager loaded credentials from the ClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones, dnsNames, matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.

This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.

All users should upgrade.

[!WARNING] …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.19.6 schließt Sicherheitslücke

cert-manager 1.19.6 behebt die Sicherheitslücke GHSA-8rvj-mm4h-c258 (HIGH), indem die ClusterRole cert-manager-edit keine Rechte mehr zum direkten Erstellen oder Ändern von Challenge- und Order-Ressourcen vergibt, was ein potenziell inkompatibler Eingriff ist, und enthält Go-Updates gegen CVEs.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release fixes a security issue (GHSA-8rvj-mm4h-c258, HIGH) where the default cert-manager-edit aggregate ClusterRole granted namespace users permission to create ACME Challenge and Order resources directly. A user who could create a Challenge referencing a ClusterIssuer could supply attacker-controlled solver configuration while cert-manager loaded credentials from the ClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones, dnsNames, matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.

This release also includes Go version bumps to address reported CVEs. All users should upgrade.

[!WARNING] Potentially breaking change: The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly.

Changes by Kind …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.21.0-alpha.1

Die Vorabversion cert-manager 1.21.0-alpha.1 (nur zum Testen) bringt unter anderem Venafi-OAuth-Beobachtbarkeit mit neuem AuthFailed-Grund, das Flag --acme-http01-solver-extra-labels, einen optionalen TTL-Cleanup für den startupapicheck-Job sowie Erweiterungen der Gateway-API-Integration und PANW-NGTS-Unterstützung.

Changes since v1.21.0-alpha.0

[!NOTE] ⚠️ This is a pre-release. For testing only!

Feature

  • Add Venafi OAuth token request observability and a new AuthFailed Issuer condition reason to distinguish bad credentials from transient infrastructure errors. (#8808, @FelixPhipps)
  • Add new controller flag --acme-http01-solver-extra-labels, allowing Helm's global.commonLabels to propagate to all dynamically-created ACME HTTP01 solver resources (Pods, Services, Ingresses, or Gateway API HTTPRoutes). (#8761, @lunarwhite)
  • Add opt-in startupapicheck.ttlSecondsAfterFinished Helm value to enable automatic cleanup of the startupapicheck Job via the Kubernetes TTL-after-finished controller. (#8523, @dap0am)
  • Added cert-manager.io/ignore-tls-listeners annotation for ignoring gwapi listeners. (#8727, @hjoshi123)
  • Added option to specify additional listener protocols the GatewayAPI integration will consider when creating certificates. (#8683, @ThatsMrTalbot)
  • Extend the Venafi/CyberArk integration to also support PANW NGTS. (#8779, @FelixPhipps)
  • Make cainjector use SSA unconditionally and deprecate the ServerSideApply feature gate (#8692, @erikgb)

Bug or Regression

  • Add dns issuer secrets validation before marking it as ready (#8255, @Peac36)
  • Add missing issuer finalizer RBAC to the order controller to support owner references (#8654, @erikgb) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.19.5

cert-manager 1.19.5 ist ein Patch-Release, der Go und Go-Abhängigkeiten mit gemeldeten Schwachstellen aktualisiert und allen Nutzern zum Upgrade empfohlen wird.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This is a simple patch release to fix some reported vulnerabilities. All users are recommended to upgrade.

Changes by Kind

Other (Cleanup or Flake)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.20.2

cert-manager 1.20.2 behebt ungültiges YAML im Helm-Chart bei gleichzeitiger Definition von webhook.config und webhook.volumes und aktualisiert Go auf 1.26.2 samt Abhängigkeiten wegen gemeldeter Schwachstellen.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.20.2 fixes invalid YAML generated in the Helm chart when both webhook.config and webhook.volumes are defined, and bumps Go to 1.26.2 along with dependencies to address reported vulnerabilities.

Changes by Kind

Bug or Regression

  • Helm: Fix invalid YAML generated when both webhook.config and webhook.volumes are defined. (#8665, @cert-manager-bot)

Other (Cleanup or Flake)

  • Bump go dependencies with reported vulnerabilities (#8704, @erikgb)
  • Bump go to 1.26.2 (#8703, @erikgb)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.20.1

cert-manager 1.20.1 behebt ein Problem mit der Finalizer-RBAC, das OpenShift-Nutzer am Upgrade auf 1.20.0 hinderte, einen doppelten parentRef-Fehler bei der Gateway API und aktualisiert gRPC wegen einer von Scannern gemeldeten Schwachstelle.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.20.1 fixes an issue for OpenShift users that has to do with the finalizer RBAC, bumps gRPC to address a reported non-affecting vulnerability, and fixes a duplicate parentRef bug when both issuer config and annotations are present (Gateway API).

Bug or Regression

  • Fixed duplicate parentRef bug when both issuer config and annotations are present. (#8658, @hjoshi123)
  • Add missing issuer finalizer RBAC to the order controller to support owner references. This was preventing OpenShift users from being able to upgrade to v1.20.0. (#8655, @erikgb)
  • Bump google.golang.org/grpc to fix vulnerability reported by scanners. This isn't a vulnerability that affects cert-manager, but we are bumping it because it is reported by scanners. (#8657, @erikgb)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.21.0-alpha.0

Die Vorabversion cert-manager 1.21.0-alpha.0 (nur zum Testen) führt Zertifikats-Erneuerungsrichtlinien ein, stuft das Feature Gate CAInjectorMerging auf GA hoch, behebt den doppelten parentRef-Fehler und entfernt die veraltete ObjectReference.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

⚠️ This is a pre-release. For testing only!

Changes by Kind since v1.20.0

Feature

  • Feat(certificate): adding certificate renewal policies (#8258, @hjoshi123)
  • Promote the CAInjectorMerging feature gate to GA (#8583, @Copilot)

Bug or Regression

  • Fixed duplicate parentRef bug when both issuer config and annotations are present. (#8619, @hjoshi123)

Other (Cleanup or Flake)

  • API cleanup: removed deprecated ObjectReference (#8625, @inteon)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.20.0

cert-manager 1.20.0 bringt Alpha-Unterstützung für ListenerSet, Azure Private DNS, optionale parentRefs bei ACME mit Gateway API, die Beförderung von OtherNames zu Beta sowie weitere Helm- und NetworkPolicy-Optionen.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.20.0 adds alpha support for the new ListenerSet resource, adds support for Azure Private DNS; parentRefs are no longer required when using ACME with Gateway API, and OtherNames was promoted to Beta.

Changes by Kind

Feature

  • Added a set of flags to permit setting NetworkPolicy across all deployed containers. Remove redundant global IP ranges from example policies. (#8370, @jcpunk)
  • Added selectable fields to custom resource definitions for .spec.issuerRef.{group, kind, name} (#8256, @tareksha)
  • Added support for specifying imagePullSecrets in the startupapicheck-job Helm template to enable pulling images from private registries. (#8186, @mathieu-clnk)
  • Added 'extraContainers' helm chart value, allowing the deployment of arbitrary sidecar containers within the cert-manager operator pod. This can be used to support, for e.g., AWS IAM Roles Anywhere for Route53 DNS01 verification. (#8355, @dancmeyers)
  • Added parentRef override annotations on the Certificate resource. (#8518, @hjoshi123)
  • Added support for azure private zones for dns01 issuer. (#8494, @hjoshi123)
  • Added support for configuring PEM decoding size limits, allowing operators to handle larger certificates and keys. (#7642, @robertlestak)
  • Added support for unhealthyPodEvictionPolicy in PodDisruptionBudget (#7728, @jcpunk) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.20.0-beta.0

Die Vorabversion cert-manager 1.20.0-beta.0 ergänzt parentRef-Override-Annotationen, Azure-Private-DNS-Unterstützung und konfigurierbare PEM-Größenlimits und behebt ein TXT-Record-Cleanup-Problem in CloudDNS sowie eine mögliche Controller-Panic durch fehlerhafte DNS-Antworten.

Changes since v1.20.0-alpha.1

In this release, parentRef override annotations, Azure private DNS zone support, and configurable PEM size limits were added, while an ACME TXT record cleanup issue in CloudDNS and a potential controller panic from malformed DNS responses were fixed.

Feature

  • Added parentRef override annotations on the Certificate resource. (#8518, @hjoshi123)
  • Added support for azure private zones for dns01 issuer. (#8494, @hjoshi123)
  • Added support for configuring PEM decoding size limits, allowing operators to handle larger certificates and keys. (#7642, @robertlestak)

Bug or Regression

  • Fix an issue where ACME challenge TXT records are not cleaned up when there are many resource records in CloudDNS. (#8456, @tkna)
  • Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. (#8469, @SgtCoDFish)

Other (Cleanup or Flake)

  • Promoting xlistenerset feature gate to listenerset (#8501, @hjoshi123)
  • Switched to SSA for challenge finalizer updates (#8519, @inteon)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.19.4

cert-manager 1.19.4 ist ein Patch-Release, das Go und das otel SDK aktualisiert, um gemeldete Schwachstellen wie CVE-2026-24051 und CVE-2025-68121 zu beheben.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.19.4 is a simple patch release to fix some reported vulnerabilities - notably CVE-2026-24051 and CVE-2025-68121. All users should upgrade.

Changes by Kind

Bug or Regression

  • Bump go to address CVE-2025-68121 (#8526, @SgtCoDFish)
  • Bump otel SDK to address GO-2026-4394 (#8531, @SgtCoDFish)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.18.6

cert-manager 1.18.6 ist ein Patch-Release, das Go aktualisiert, um CVE-2025-68121 zu beheben, während CVE-2026-24051 nicht gepatcht wurde, da es nur macOS betrifft.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.18.6 is a simple patch release to fix some reported vulnerabilities, most notably CVE-2025-68121.

NB: We didn't attempt to patch CVE-2026-24051 but that vulnerability affects macOS only, so cert-manager will be unaffected.

Changes by Kind

Bug or Regression

  • Bump Go to address CVE-2025-68121 (#8525, @SgtCoDFish)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.19.3

cert-manager 1.19.3 behebt eine Endlos-Neuausstellungsschleife bei nicht zur CSR passendem Public Key, HTTP-01-Challenges mit IPv6-Adressen im Host-Header sowie eine DoS-Lücke mittleren Schweregrads (GHSA-gx3x-vq4p-mhhv) und aktualisiert Go auf 1.25.6.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.

Changes by Kind

Bug or Regression

  • Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. (#8415, @cert-manager-bot)
  • Fixed an issue where HTTP-01 challenges failed when the Host header contained an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. (#8436, @cert-manager-bot)
  • Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. (#8468, @SgtCoDFish)

Other (Cleanup or Flake)

  • Bump go to 1.25.6 (#8459, @SgtCoDFish)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.18.5

cert-manager 1.18.5 behebt eine Endlos-Neuausstellungsschleife bei nicht zur CSR passendem Public Key, HTTP-01-Challenges mit IPv6-Adressen im Host-Header sowie eine DoS-Lücke mittleren Schweregrads (GHSA-gx3x-vq4p-mhhv) und aktualisiert Go auf 1.24.12.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.

Changes by Kind

Bug or Regression

  • Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. (#8414, @cert-manager-bot)
  • Fixed an issue where HTTP-01 challenges failed when the Host header contains an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. (#8437, @cert-manager-bot)
  • Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. (#8467, @SgtCoDFish)

Other (Cleanup or Flake)

  • Bump go to 1.24.12 (#8460, @SgtCoDFish)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.20.0-alpha.1

Die Vorabversion cert-manager 1.20.0-alpha.1 bringt experimentelle XListenerSet-Unterstützung, NetworkPolicy-Flags und wählbare CRD-Felder, behebt die Endlos-Neuausstellungsschleife und IPv6-HTTP-01-Probleme, stuft OtherNames auf Beta und DefaultPrivateKeyRotationPolicyAlways auf GA hoch und ändert die Standard-UID/GID des Containers auf 65532/65532.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This is a pre-release for cert-manager v1.20.0. Please help with testing!

Changed since v1.20.0-alpha.0

This alpha release adds experimental XListenerSet support, NetworkPolicy and CRD selectable field features, fixes critical bugs including an infinite re-issuance loop and IPv6 HTTP-01 challenge issues, patches security vulnerabilities (CVE-2025-61727, CVE-2025-61729), promotes OtherNames to Beta and DefaultPrivateKeyRotationPolicyAlways to GA, and changes the default container UID/GID from 1000/0 to 65532/65532.

Feature

  • Added experimental XListenerSet feature gate (#8394, @hjoshi123)
  • Add a set of flags to permit setting NetworkPolicy across all deployed containers. Remove redundant global IP ranges from example policies. (#8370, @jcpunk)
  • Add selectable fields to custom resource definitions for .spec.issuerRef.{group, kind, name} (#8256, @tareksha)
  • Added 'extraContainers' helm chart value, allowing the deployment of arbitrary sidecar containers within the cert-manager operator pod. This can be used to support, for e.g., AWS IAM Roles Anywhere for Route53 DNS01 verification. (#8355, @dancmeyers)
  • Added support for unhealthyPodEvictionPolicy in PodDisruptionBudget (#7728, @jcpunk) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager 1.19.2

cert-manager 1.19.2 aktualisiert Go auf 1.25.5 zur Behebung von CVE-2025-61727 und CVE-2025-61729, erlaubt ein per merge zusammengeführtes global.nodeSelector im Helm-Chart und aktualisiert den ACME-Client sowie die Debian-12-distroless-Basisimages.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We updated Go to fix some vulnerabilities in the standard library.

📖 Read the full 1.19 release notes on the cert-manager.io website before upgrading.

Changes since v1.19.1

Bug or Regression

  • Address false positive vulnerabilities CVE-2025-47914 and CVE-2025-58181 which were reported by Trivy. (#8283, @SgtCoDFish)
  • Update Go to v1.25.5 to fix CVE-2025-61727 and CVE-2025-61729 (#8294, @wallrj-cyberark)
  • Update global.nodeSelector to helm chart to perform a merge and allow for a single nodeSelector to be set across all services. (#8233, @cert-manager-bot)

Other (Cleanup or Flake)

  • Update cert-manager's ACME client, forked from golang/x/crypto (#8270, @SgtCoDFish)
  • Updated Debian 12 distroless base images (#8326, @wallrj-cyberark)

Originalquelle(öffnet in neuem Tab)Problem melden