enterprise-2.19.10
August 10, 2026
The 2.19.10 point release fixes an issue with FIPS connections from the control plane to the Kubernetes API. This release also updates some dependencies to address reported CVEs in underlying components.
Previous release: enterprise-2.19.9.
Supported Kubernetes versions
For this release, the minimum supported Kubernetes version remains 1.29, and the maximum supported Kubernetes version remains 1.35.
Who should upgrade?
Users who run the FIPS-validated version of BEL should upgrade to this release when feasible.
Other users may upgrade to this release at their convenience to take advantage of the addressed CVEs.
Upgrade guidance
This is a stable point release designed to introduce minimal change. Please see the instructions in Upgrading BEL for how to upgrade.
To upgrade with BEL’s lifecycle automation operator, you will need Buoyant Extension v0.40.5 or later.
Changelog
- Fixed an issue with FIPS connections from the control plane to the Kubernetes API.
- Update
golangto remediate- GO-2026-5856 (maps to CVE-2026-42505)
- GO-2026-4970 (maps to CVE-2026-39822)
- Update
golang.org/x/textto remediate- GO-2026-5970 (maps to CVE-2026-56852)
- Update
github.com/klauspost/compressto remediate - Update
go.opentelemetry.io/otelto remediate- GO-2026-5158 (maps to CVE-2026-41178)
- Update
oras.land/oras-go/v2to remediate - Update
google.golang.org/grpcto remediate - Update
opentelemetryto remediate - Update
rustls-webpkidependency to remediate - Update to
hickory-prototo remediate