enterprise-2.20.2
August 26, 2026
The 2.20.2 stable point release adds official support for Kubernetes 1.36 and Gateway API v1.5.1, and fixes a HAZL bug that caused a small amount of traffic to always be routed cross-zone. This release also updates some dependencies to address reported CVEs in underlying components.
Previous release: enterprise-2.20.1.
Supported Kubernetes versions
For this release, the minimum supported Kubernetes version remains 1.31, and the maximum supported Kubernetes version has been increased to 1.36.
Who should upgrade?
Users who have HAZL enabled should upgrade as soon as possible, as this release corrects zone spillage along with the connection churn and elevated proxy CPU that accompanied it. Users running Kubernetes 1.36 or Gateway API v1.5.1 should also upgrade.
Other users may upgrade to this release at their convenience to take advantage of the fixes and addressed CVEs.
Upgrade guidance
This is a stable point release designed to introduce minimal change. Please see the instructions in Upgrading BEL for how to upgrade.
To upgrade with BEL’s lifecycle automation operator, you will need Buoyant Extension v0.40.5 or later.
Changelog
- Added official support for Kubernetes 1.36.
- Added support for Gateway API v1.5.1.
- Fixed a HAZL bug where a small amount of traffic was always sent cross-zone, causing endpoint and connection churn that increased latency and proxy CPU usage.
- Update
golangto remediate - Update
oras.land/oras-go/v2to remediate - Update
github.com/klauspost/compressto remediate - Update
go.opentelemetry.io/otelto remediate- GO-2026-5158 (maps to CVE-2026-41178)