Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
KEDA 2.21.0: Drei Breaking Changes und Fix für CVE-2026-77524
KEDA 2.21.0 bringt drei Breaking Changes und behebt die kritische Sicherheitslücke CVE-2026-77524, indem die Audience von Service-Account-Tokens (u. a. Vault Kubernetes Authentication und boundServiceAccountToken in TriggerAuthentication) erzwungen wird; vor dem Upgrade von 2.20 ist der Upgrade-Leitfaden zu beachten.
We are happy to release KEDA 2.21.0 🎉
[!IMPORTANT] KEDA 2.21.0 contains three breaking changes. If you are upgrading from KEDA 2.20, review Upgrading from KEDA 2.20 to 2.21 before upgrading.
Before upgrading from KEDA 2.20
Service account token audience enforcement (CVE-2026-77524)
KEDA 2.21 fixes the critical CVE-2026-77524 / GHSA-637c-6jxx-4rwm. You are affected if you use:
- Vault Kubernetes authentication, including configurations using the operator token, an existing projected token, or
credential.serviceAccountName. - Any
TriggerAuthenticationorClusterTriggerAuthenticationusingboundServiceAccountToken, including integrations with Metrics API, Prometheus, Loki, Datadog Cluster Agent, and other token-authenticated receivers.
You are not affected if you use ordinary Vault token authentication, API keys, OAuth credentials, or another authentication method that does not use a bound service account token. Before upgrading, review carefully the upgrade guide