<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Buoyant Enterprise for Linkerd | Release notes</title><link>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/</link><description>Recent releases for Buoyant Enterprise for Linkerd</description><language>en</language><lastBuildDate>Wed, 26 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/index.xml" rel="self" type="application/rss+xml"/><item><title>enterprise-2.20.2</title><link>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.20.2/</link><pubDate>Wed, 26 Aug 2026 00:00:00 +0000</pubDate><guid>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.20.2/</guid><description>&lt;p&gt;The 2.20.2 stable point release adds official support for Kubernetes 1.36 and
Gateway API v1.5.1, and fixes a HAZL bug that caused a small amount of traffic
to always be routed cross-zone. This release also updates some dependencies to
address reported CVEs in underlying components.&lt;/p&gt;
&lt;p&gt;Previous release: &lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.20.1/"&gt;enterprise-2.20.1&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;
Supported Kubernetes versions
&lt;/h2&gt;
&lt;p&gt;For this release, the minimum supported Kubernetes version remains 1.31, and the
maximum supported Kubernetes version has been increased to 1.36.&lt;/p&gt;
&lt;h2&gt;
Who should upgrade?
&lt;/h2&gt;
&lt;p&gt;Users who have HAZL enabled should upgrade as soon as possible, as this release
corrects zone spillage along with the connection churn and elevated proxy CPU
that accompanied it. Users running Kubernetes 1.36 or Gateway API v1.5.1 should
also upgrade.&lt;/p&gt;
&lt;p&gt;Other users may upgrade to this release at their convenience to take advantage
of the fixes and addressed CVEs.&lt;/p&gt;
&lt;h2&gt;
Upgrade guidance
&lt;/h2&gt;
&lt;p&gt;This is a stable point release designed to introduce minimal change. Please see
the instructions in &lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/2.20/upgrade/"&gt;Upgrading BEL&lt;/a&gt;
for how to upgrade.&lt;/p&gt;
&lt;p&gt;To upgrade with &lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/latest/features/operator/"&gt;BEL’s lifecycle automation operator&lt;/a&gt;, you will need Buoyant Extension &lt;a href="https://docs.buoyant.io/release-notes/buoyant-extension/v0.40.5/"&gt;v0.40.5&lt;/a&gt; or later.&lt;/p&gt;
&lt;h2&gt;
Changelog
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added official support for Kubernetes 1.36.&lt;/li&gt;
&lt;li&gt;Added support for Gateway API v1.5.1.&lt;/li&gt;
&lt;li&gt;Fixed a HAZL bug where a small amount of traffic was always sent cross-zone,
causing endpoint and connection churn that increased latency and proxy CPU
usage.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;golang&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6218" rel="noopener" target="_blank"&gt;GO-2026-6218&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6091" rel="noopener" target="_blank"&gt;GO-2026-6091&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6090" rel="noopener" target="_blank"&gt;GO-2026-6090&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6089" rel="noopener" target="_blank"&gt;GO-2026-6089&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6088" rel="noopener" target="_blank"&gt;GO-2026-6088&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5972" rel="noopener" target="_blank"&gt;GO-2026-5972&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5026" rel="noopener" target="_blank"&gt;GO-2026-5026&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;oras.land/oras-go/v2&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-fxhp-mv3v-67qp" rel="noopener" target="_blank"&gt;GHSA-fxhp-mv3v-67qp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;github.com/klauspost/compress&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5841" rel="noopener" target="_blank"&gt;GO-2026-5841&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;go.opentelemetry.io/otel&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5158" rel="noopener" target="_blank"&gt;GO-2026-5158&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41178" rel="noopener" target="_blank"&gt;CVE-2026-41178&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>enterprise-2.18.13</title><link>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.18.13/</link><pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate><guid>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.18.13/</guid><description>&lt;p&gt;The 2.18.13 stable point release updates some dependencies to address reported
CVEs in underlying components.&lt;/p&gt;
&lt;div class="alert alert--warning"&gt;
&lt;div class="alert__icon"&gt;&lt;svg class="icon icon--warning" width="24" height="24" viewBox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"&gt;
&lt;path d="M13 14H11V9H13M13 18H11V16H13M1 21H23L12 2L1 21Z" fill="#818181" /&gt;
&lt;/svg&gt;&lt;/div&gt;
&lt;div class="alert__body"&gt;
FIPS users who are upgrading from 2.18 to 2.19 must
follow a specific sequence to preserve zero-downtime upgrades. You must first
upgrade to &lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.18.7/"&gt;2.18.7&lt;/a&gt; or later, and then to
&lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.19.4/"&gt;2.19.4&lt;/a&gt; or later.
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Previous release: &lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.18.12/"&gt;enterprise-2.18.12&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;
Supported Kubernetes versions
&lt;/h2&gt;
&lt;p&gt;For this release, the minimum supported Kubernetes version remains 1.22, and the
maximum supported Kubernetes version remains 1.32.&lt;/p&gt;
&lt;h2&gt;
Who should upgrade?
&lt;/h2&gt;
&lt;p&gt;This is a CVE hygiene release and does not fix any known exploitable
vulnerabilities with Linkerd. Users may upgrade to this release at their
convenience.&lt;/p&gt;
&lt;h2&gt;
Upgrade guidance
&lt;/h2&gt;
&lt;p&gt;This is a stable point release designed to introduce minimal change. Please see
the instructions in &lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/2.18/upgrade/"&gt;Upgrading BEL&lt;/a&gt;
for how to upgrade.&lt;/p&gt;
&lt;p&gt;To upgrade with &lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/latest/features/operator/"&gt;BEL’s lifecycle automation operator&lt;/a&gt;, you will need Buoyant Extension &lt;a href="https://docs.buoyant.io/release-notes/buoyant-extension/v0.40.5/"&gt;v0.40.5&lt;/a&gt; or later.&lt;/p&gt;
&lt;h2&gt;
Changelog
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Update &lt;code&gt;golang&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6218" rel="noopener" target="_blank"&gt;GO-2026-6218&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6091" rel="noopener" target="_blank"&gt;GO-2026-6091&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6090" rel="noopener" target="_blank"&gt;GO-2026-6090&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6089" rel="noopener" target="_blank"&gt;GO-2026-6089&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-6088" rel="noopener" target="_blank"&gt;GO-2026-6088&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5972" rel="noopener" target="_blank"&gt;GO-2026-5972&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5942" rel="noopener" target="_blank"&gt;GO-2026-5942&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5856" rel="noopener" target="_blank"&gt;GO-2026-5856&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42505" rel="noopener" target="_blank"&gt;CVE-2026-42505&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5026" rel="noopener" target="_blank"&gt;GO-2026-5026&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-4970" rel="noopener" target="_blank"&gt;GO-2026-4970&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39822" rel="noopener" target="_blank"&gt;CVE-2026-39822&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;oras.land/oras-go/v2&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-vh4v-2xq2-g5cg" rel="noopener" target="_blank"&gt;GHSA-vh4v-2xq2-g5cg&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-jxpm-75mh-9fp7" rel="noopener" target="_blank"&gt;GHSA-jxpm-75mh-9fp7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-8xwf-rjm4-xvhv" rel="noopener" target="_blank"&gt;GHSA-8xwf-rjm4-xvhv&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;google.golang.org/grpc&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-hrxh-6v49-42gf" rel="noopener" target="_blank"&gt;GHSA-hrxh-6v49-42gf&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;openssl&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-xv59-967r-8726" rel="noopener" target="_blank"&gt;GHSA-xv59-967r-8726&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-xp3w-r5p5-63rr" rel="noopener" target="_blank"&gt;GHSA-xp3w-r5p5-63rr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-pqf5-4pqq-29f5" rel="noopener" target="_blank"&gt;GHSA-pqf5-4pqq-29f5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-phqj-4mhp-q6mq" rel="noopener" target="_blank"&gt;GHSA-phqj-4mhp-q6mq&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-hppc-g8h3-xhp3" rel="noopener" target="_blank"&gt;GHSA-hppc-g8h3-xhp3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-ghm9-cr32-g9qj" rel="noopener" target="_blank"&gt;GHSA-ghm9-cr32-g9qj&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-8c75-8mhr-p7r9" rel="noopener" target="_blank"&gt;GHSA-8c75-8mhr-p7r9&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;opentelemetry&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-w9wp-h8wv-79jx" rel="noopener" target="_blank"&gt;GHSA-w9wp-h8wv-79jx&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;rustls-webpki&lt;/code&gt; dependency to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-82j2-j2ch-gfr8" rel="noopener" target="_blank"&gt;GHSA-82j2-j2ch-gfr8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-pwjx-qhcg-rvj4" rel="noopener" target="_blank"&gt;GHSA-pwjx-qhcg-rvj4&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update to &lt;code&gt;hickory-proto&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-q2qq-hmj6-3wpp" rel="noopener" target="_blank"&gt;GHSA-q2qq-hmj6-3wpp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;time&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-r6v5-fh4h-64xc" rel="noopener" target="_blank"&gt;GHSA-r6v5-fh4h-64xc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;bytes&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-434x-w66g-qw3r" rel="noopener" target="_blank"&gt;GHSA-434x-w66g-qw3r&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>enterprise-2.19.10</title><link>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.19.10/</link><pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate><guid>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.19.10/</guid><description>&lt;p&gt;The 2.19.10 point release fixes an issue with FIPS connections from the control
plane to the Kubernetes API. This release also updates some dependencies to
address reported CVEs in underlying components.&lt;/p&gt;
&lt;div class="alert alert--warning"&gt;
&lt;div class="alert__icon"&gt;&lt;svg class="icon icon--warning" width="24" height="24" viewBox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"&gt;
&lt;path d="M13 14H11V9H13M13 18H11V16H13M1 21H23L12 2L1 21Z" fill="#818181" /&gt;
&lt;/svg&gt;&lt;/div&gt;
&lt;div class="alert__body"&gt;
FIPS users who are upgrading from 2.18 to 2.19 must
follow a specific sequence to preserve zero-downtime upgrades. You must first
upgrade to &lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.18.7/"&gt;2.18.7&lt;/a&gt; or later, and then to
&lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.19.4/"&gt;2.19.4&lt;/a&gt; or later.
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Previous release: &lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.19.9/"&gt;enterprise-2.19.9&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;
Supported Kubernetes versions
&lt;/h2&gt;
&lt;p&gt;For this release, the minimum supported Kubernetes version remains 1.29, and the
maximum supported Kubernetes version remains 1.35.&lt;/p&gt;
&lt;h2&gt;
Who should upgrade?
&lt;/h2&gt;
&lt;p&gt;Users who run the FIPS-validated version of BEL should upgrade to this release
when feasible.&lt;/p&gt;
&lt;p&gt;Other users may upgrade to this release at their convenience to take advantage
of the addressed CVEs.&lt;/p&gt;
&lt;h2&gt;
Upgrade guidance
&lt;/h2&gt;
&lt;p&gt;This is a stable point release designed to introduce minimal change. Please see
the instructions in &lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/2.19/upgrade/"&gt;Upgrading BEL&lt;/a&gt;
for how to upgrade.&lt;/p&gt;
&lt;p&gt;To upgrade with &lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/latest/features/operator/"&gt;BEL’s lifecycle automation operator&lt;/a&gt;, you will need Buoyant Extension &lt;a href="https://docs.buoyant.io/release-notes/buoyant-extension/v0.40.5/"&gt;v0.40.5&lt;/a&gt; or later.&lt;/p&gt;
&lt;h2&gt;
Changelog
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue with FIPS connections from the control plane to the Kubernetes
API.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;golang&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5856" rel="noopener" target="_blank"&gt;GO-2026-5856&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42505" rel="noopener" target="_blank"&gt;CVE-2026-42505&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-4970" rel="noopener" target="_blank"&gt;GO-2026-4970&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39822" rel="noopener" target="_blank"&gt;CVE-2026-39822&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;golang.org/x/text&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5970" rel="noopener" target="_blank"&gt;GO-2026-5970&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-56852" rel="noopener" target="_blank"&gt;CVE-2026-56852&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;github.com/klauspost/compress&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5841" rel="noopener" target="_blank"&gt;GO-2026-5841&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;go.opentelemetry.io/otel&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5158" rel="noopener" target="_blank"&gt;GO-2026-5158&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41178" rel="noopener" target="_blank"&gt;CVE-2026-41178&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;oras.land/oras-go/v2&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-fxhp-mv3v-67qp" rel="noopener" target="_blank"&gt;GHSA-fxhp-mv3v-67qp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-vh4v-2xq2-g5cg" rel="noopener" target="_blank"&gt;GHSA-vh4v-2xq2-g5cg&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-jxpm-75mh-9fp7" rel="noopener" target="_blank"&gt;GHSA-jxpm-75mh-9fp7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-8xwf-rjm4-xvhv" rel="noopener" target="_blank"&gt;GHSA-8xwf-rjm4-xvhv&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;google.golang.org/grpc&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-hrxh-6v49-42gf" rel="noopener" target="_blank"&gt;GHSA-hrxh-6v49-42gf&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;opentelemetry&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-w9wp-h8wv-79jx" rel="noopener" target="_blank"&gt;GHSA-w9wp-h8wv-79jx&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;rustls-webpki&lt;/code&gt; dependency to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-82j2-j2ch-gfr8" rel="noopener" target="_blank"&gt;GHSA-82j2-j2ch-gfr8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-pwjx-qhcg-rvj4" rel="noopener" target="_blank"&gt;GHSA-pwjx-qhcg-rvj4&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update to &lt;code&gt;hickory-proto&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-q2qq-hmj6-3wpp" rel="noopener" target="_blank"&gt;GHSA-q2qq-hmj6-3wpp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>enterprise-2.20.1</title><link>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.20.1/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.20.1/</guid><description>&lt;p&gt;The 2.20.1 stable point release fixes a panic in &lt;code&gt;linkerd policy generate&lt;/code&gt;, and
fixes a corner case in proxy behavior where connections to undefined service
ports were incorrectly allowed if a corresponding ServiceProfile existed for
that Service. This release also updates dependencies to address reported CVEs in
underlying components, and provides optional FIPS binaries.&lt;/p&gt;
&lt;p&gt;This release technically contains a minor breaking change, in service of
conforming to the stated documentation. Since Linkerd 2.19, the documented
behavior with respect to ports that are &lt;em&gt;not&lt;/em&gt; declared in a Service spec is to
match the behavior of kubeproxy: Linkerd should deny connections to those ports.
However, the original implementation of this behavior incorrectly &lt;em&gt;allowed&lt;/em&gt;
those connections if a &lt;code&gt;ServiceProfile&lt;/code&gt; existed.&lt;/p&gt;
&lt;p&gt;In this release, we&amp;rsquo;ve fixed Linkerd&amp;rsquo;s behavior to match the documentation:
connections to ports that are not defined in the Service spec are now denied,
even when a ServiceProfile exists for that Service. See
&lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.20.1/#upgrade-guidance"&gt;Upgrade guidance&lt;/a&gt; below for details.&lt;/p&gt;
&lt;p&gt;Previous release: &lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.20.0/"&gt;enterprise-2.20.0&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;
Supported Kubernetes versions
&lt;/h2&gt;
&lt;p&gt;For this release, the minimum supported Kubernetes version remains 1.31, and the
maximum supported Kubernetes version remains 1.35.&lt;/p&gt;
&lt;h2&gt;
Who should upgrade?
&lt;/h2&gt;
&lt;p&gt;Customers who require FIPS support or need bug fixes introduced in 2.20 should
upgrade when feasible.&lt;/p&gt;
&lt;p&gt;Other users may upgrade to this release at their convenience to take advantage
of the fixes and addressed CVEs.&lt;/p&gt;
&lt;h2&gt;
Upgrade guidance
&lt;/h2&gt;
&lt;p&gt;Customers who use ServiceProfiles &lt;em&gt;and&lt;/em&gt; currently connect to ports on Services
that are &lt;em&gt;not&lt;/em&gt; defined in the Service spec should add those ports to the
corresponding Service spec before upgrading. All other customers can upgrade
safely without changes.&lt;/p&gt;
&lt;p&gt;See the instructions in
&lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/2.20/upgrade/"&gt;Upgrading BEL&lt;/a&gt; for how to upgrade.&lt;/p&gt;
&lt;p&gt;To upgrade with &lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/latest/features/operator/"&gt;BEL’s lifecycle automation operator&lt;/a&gt;, you will need Buoyant Extension &lt;a href="https://docs.buoyant.io/release-notes/buoyant-extension/v0.40.3/"&gt;v0.40.3&lt;/a&gt; or later.&lt;/p&gt;
&lt;h2&gt;
Changelog
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Breaking change:&lt;/strong&gt; Meshed connections to a ClusterIP Service on a port
absent from the Service&amp;rsquo;s spec are now denied even when a ServiceProfile is
defined for that Service, matching documentation.
[&lt;a href="https://github.com/linkerd/linkerd2/pull/15473" rel="noopener" target="_blank"&gt;#15473&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;Fixed panic in &lt;code&gt;linkerd policy generate&lt;/code&gt; command, and add support for proxies
injected in (the now default) native sidecar mode.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;golang&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5856" rel="noopener" target="_blank"&gt;GO-2026-5856&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42505" rel="noopener" target="_blank"&gt;CVE-2026-42505&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-4970" rel="noopener" target="_blank"&gt;GO-2026-4970&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39822" rel="noopener" target="_blank"&gt;CVE-2026-39822&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;golang.org/x/text&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pkg.go.dev/vuln/GO-2026-5970" rel="noopener" target="_blank"&gt;GO-2026-5970&lt;/a&gt; (maps to
&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-56852" rel="noopener" target="_blank"&gt;CVE-2026-56852&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;oras.land/oras-go/v2&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-vh4v-2xq2-g5cg" rel="noopener" target="_blank"&gt;GHSA-vh4v-2xq2-g5cg&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-jxpm-75mh-9fp7" rel="noopener" target="_blank"&gt;GHSA-jxpm-75mh-9fp7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-8xwf-rjm4-xvhv" rel="noopener" target="_blank"&gt;GHSA-8xwf-rjm4-xvhv&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;google.golang.org/grpc&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-hrxh-6v49-42gf" rel="noopener" target="_blank"&gt;GHSA-hrxh-6v49-42gf&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;opentelemetry&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-w9wp-h8wv-79jx" rel="noopener" target="_blank"&gt;GHSA-w9wp-h8wv-79jx&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;libcrypt&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6791" rel="noopener" target="_blank"&gt;CVE-2026-6791&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>enterprise-2.18.12</title><link>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.18.12/</link><pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate><guid>https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.18.12/</guid><description>&lt;p&gt;The 2.18.12 stable point release updates some dependencies to address reported
CVEs in underlying components.&lt;/p&gt;
&lt;div class="alert alert--warning"&gt;
&lt;div class="alert__icon"&gt;&lt;svg class="icon icon--warning" width="24" height="24" viewBox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"&gt;
&lt;path d="M13 14H11V9H13M13 18H11V16H13M1 21H23L12 2L1 21Z" fill="#818181" /&gt;
&lt;/svg&gt;&lt;/div&gt;
&lt;div class="alert__body"&gt;
FIPS users who are upgrading from 2.18 to 2.19 must
follow a specific sequence to preserve zero-downtime upgrades. You must first
upgrade to &lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.18.7/"&gt;2.18.7&lt;/a&gt; or later, and then to
&lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.19.4/"&gt;2.19.4&lt;/a&gt; or later.
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Previous release: &lt;a href="https://docs.buoyant.io/release-notes/buoyant-enterprise-linkerd/enterprise-2.18.11/"&gt;enterprise-2.18.11&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;
Supported Kubernetes versions
&lt;/h2&gt;
&lt;p&gt;For this release, the minimum supported Kubernetes version remains 1.22, and the
maximum supported Kubernetes version remains 1.32.&lt;/p&gt;
&lt;h2&gt;
Who should upgrade?
&lt;/h2&gt;
&lt;p&gt;This is a CVE hygiene release and does not fix any known exploitable
vulnerabilities with Linkerd. Users may upgrade to this release at their
convenience.&lt;/p&gt;
&lt;h2&gt;
Upgrade guidance
&lt;/h2&gt;
&lt;p&gt;This is a stable point release designed to introduce minimal change. Please see
the instructions in &lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/2.18/upgrade/"&gt;Upgrading BEL&lt;/a&gt;
for how to upgrade.&lt;/p&gt;
&lt;p&gt;To upgrade with &lt;a href="https://docs.buoyant.io/buoyant-enterprise-linkerd/latest/features/operator/"&gt;BEL’s lifecycle automation operator&lt;/a&gt;, you will need Buoyant Extension &lt;a href="https://docs.buoyant.io/release-notes/buoyant-extension/v0.40.1/"&gt;v0.40.1&lt;/a&gt; or later.&lt;/p&gt;
&lt;h2&gt;
Changelog
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Update &lt;code&gt;golang&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42507" rel="noopener" target="_blank"&gt;CVE-2026-42507&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42504" rel="noopener" target="_blank"&gt;CVE-2026-42504&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27145" rel="noopener" target="_blank"&gt;CVE-2026-27145&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33814" rel="noopener" target="_blank"&gt;CVE-2026-33814&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;golang.org/x/tools&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46598" rel="noopener" target="_blank"&gt;CVE-2026-46598&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46595" rel="noopener" target="_blank"&gt;CVE-2026-46595&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42508" rel="noopener" target="_blank"&gt;CVE-2026-42508&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39834" rel="noopener" target="_blank"&gt;CVE-2026-39834&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39831" rel="noopener" target="_blank"&gt;CVE-2026-39831&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39829" rel="noopener" target="_blank"&gt;CVE-2026-39829&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39830" rel="noopener" target="_blank"&gt;CVE-2026-39830&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39827" rel="noopener" target="_blank"&gt;CVE-2026-39827&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39835" rel="noopener" target="_blank"&gt;CVE-2026-39835&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39828" rel="noopener" target="_blank"&gt;CVE-2026-39828&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46597" rel="noopener" target="_blank"&gt;CVE-2026-46597&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39832" rel="noopener" target="_blank"&gt;CVE-2026-39832&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39833" rel="noopener" target="_blank"&gt;CVE-2026-39833&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27136" rel="noopener" target="_blank"&gt;CVE-2026-27136&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25681" rel="noopener" target="_blank"&gt;CVE-2026-25681&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25680" rel="noopener" target="_blank"&gt;CVE-2026-25680&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42502" rel="noopener" target="_blank"&gt;CVE-2026-42502&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39821" rel="noopener" target="_blank"&gt;CVE-2026-39821&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42506" rel="noopener" target="_blank"&gt;CVE-2026-42506&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;github.com/containerd/containerd&lt;/code&gt; dependency to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-jpcc-p29g-p8mq" rel="noopener" target="_blank"&gt;GHSA-jpcc-p29g-p8mq&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/advisories/GHSA-xhf5-7wjv-pqxp" rel="noopener" target="_blank"&gt;GHSA-xhf5-7wjv-pqxp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;libssl3&lt;/code&gt; to remediate
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42769" rel="noopener" target="_blank"&gt;CVE-2026-42769&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42767" rel="noopener" target="_blank"&gt;CVE-2026-42767&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42764" rel="noopener" target="_blank"&gt;CVE-2026-42764&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34183" rel="noopener" target="_blank"&gt;CVE-2026-34183&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34181" rel="noopener" target="_blank"&gt;CVE-2026-34181&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9076" rel="noopener" target="_blank"&gt;CVE-2026-9076&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7383" rel="noopener" target="_blank"&gt;CVE-2026-7383&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45447" rel="noopener" target="_blank"&gt;CVE-2026-45447&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45446" rel="noopener" target="_blank"&gt;CVE-2026-45446&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45445" rel="noopener" target="_blank"&gt;CVE-2026-45445&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42766" rel="noopener" target="_blank"&gt;CVE-2026-42766&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34182" rel="noopener" target="_blank"&gt;CVE-2026-34182&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34180" rel="noopener" target="_blank"&gt;CVE-2026-34180&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>