Kubernetes
banner
kubernetes.io
Kubernetes
@kubernetes.io
#Kubernetes: open source production-grade container orchestration management. #CNCF #K8s
CVE-2025-15566: ingress-nginx auth-proxy-set-headers nginx configuration injection -
CVE-2025-15566: ingress-nginx auth-proxy-set-headers nginx configuration injection · Issue #136789 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H A security issue was discovered in ingress-nginx where the nginx.ingress.kubernetes.io/auth-proxy-set-headers Ingress annotation can be use...
github.com
February 6, 2026 at 4:06 PM
Last Week in Kubernetes Development: Week Ending February 1, 2026 -
Week Ending February 1, 2026
Developer News
lwkd.info
February 5, 2026 at 8:52 PM
CVE-2026-24514: ingress-nginx Admission Controller denial of service -
CVE-2026-24514: ingress-nginx Admission Controller denial of service · Issue #136680 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condit...
github.com
February 4, 2026 at 8:52 PM
CVE-2026-24513: ingress-nginx auth-url protection bypass -
CVE-2026-24513: ingress-nginx auth-url protection bypass · Issue #136679 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N A security issue was discovered in ingress-nginx where the protection afforded by the auth-url Ingress annotation may not be effective in t...
github.com
February 4, 2026 at 4:06 PM
CVE-2026-24512: ingress-nginx rules.http.paths.path nginx configuration injection -
CVE-2026-24512: ingress-nginx rules.http.paths.path nginx configuration injection · Issue #136678 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H A security issue was discovered in ingress-nginx where the rules.http.paths.path Ingress field can be used to inject configuration into ngi...
github.com
February 3, 2026 at 8:52 PM
CVE-2026-1580: ingress-nginx auth-method nginx configuration injection -
CVE-2026-1580: ingress-nginx auth-method nginx configuration injection · Issue #136677 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H A security issue was discovered in ingress-nginx where the nginx.ingress.kubernetes.io/auth-method Ingress annotation can be used to inject...
github.com
February 3, 2026 at 4:06 PM
Kubernetes New Contributor Orientation is typically held on the third Tuesday of each month, in two timezones. Check out k8s.dev/calendar to add the next session to your calendar, and get started contributing!
Community Calendar
Meetings in the Kubernetes Community
k8s.dev
February 2, 2026 at 8:52 PM
New Conversion from cgroup v1 CPU Shares to v2 CPU Weight-
New Conversion from cgroup v1 CPU Shares to v2 CPU Weight
I'm excited to announce the implementation of an improved conversion formula from cgroup v1 CPU shares to cgroup v2 CPU weight. This enhancement addresses critical issues with CPU priority allocation...
kubernetes.io
February 2, 2026 at 4:06 PM
Last Week in Kubernetes Development: Week Ending January 25, 2026 -
Week Ending January 25, 2026
Developer News
lwkd.info
January 30, 2026 at 4:06 PM
Ingress NGINX: Statement from the Kubernetes Steering and Security Response Committees-
Ingress NGINX: Statement from the Kubernetes Steering and Security Response Committees
In March 2026, Kubernetes will retire Ingress NGINX, a piece of critical infrastructure for about half of cloud native environments. The retirement of Ingress NGINX was announced for March 2026, after...
kubernetes.io
January 29, 2026 at 8:52 PM
Experimenting with Gateway API using kind-
Experimenting with Gateway API using kind
This document will guide you through setting up a local experimental environment with Gateway API on kind. This setup is designed for learning and testing. It helps you understand Gateway API concepts...
kubernetes.io
January 28, 2026 at 8:52 PM
Cluster API v1.12: Introducing In-place Updates and Chained Upgrades-
Cluster API v1.12: Introducing In-place Updates and Chained Upgrades
Cluster API brings declarative management to Kubernetes cluster lifecycle, allowing users and platform teams to define the desired state of clusters and rely on controllers to continuously reconcile toward...
kubernetes.io
January 28, 2026 at 4:06 PM
Last Week in Kubernetes Development: Week Ending January 18, 2026 -
Week Ending January 18, 2026
Developer News
lwkd.info
January 23, 2026 at 4:06 PM
Announcing the Checkpoint/Restore Working Group-
Announcing the Checkpoint/Restore Working Group
The community around Kubernetes includes a number of Special Interest Groups (SIGs) and Working Groups (WGs) facilitating discussions on important topics between interested contributors. Today we would...
kubernetes.io
January 22, 2026 at 4:06 PM
Blog: Announcing the Checkpoint/Restore Working Group-
Announcing the Checkpoint/Restore Working Group
The community around Kubernetes includes a number of Special Interest Groups (SIGs) and Working Groups (WGs) facilitating discussions on important topics between interested contributors. Today we would...
www.kubernetes.dev
January 21, 2026 at 4:06 PM
Ingress NGINX is being retired in March 2026.
After this date, no security patches or bugfixes will be issued. Plan your migration to Gateway API or a supported controller now.

Read the retirement guide: kubernetes.io/blog/2025/11...
Ingress NGINX Retirement: What You Need to Know
To prioritize the safety and security of the ecosystem, Kubernetes SIG Network and the Security Response Committee are announcing the upcoming retirement of Ingress NGINX. Best-effort maintenance…
kubernetes.io
January 20, 2026 at 8:52 PM
Uniform API server access using clientcmd-
Uniform API server access using clientcmd
If you've ever wanted to develop a command line client for a Kubernetes API, especially if you've considered making your client usable as a kubectl plugin, you might have wondered how to make your client...
kubernetes.io
January 20, 2026 at 4:06 PM
Kubernetes New Contributor Orientation is typically held on the third Tuesday of each month, in two timezones. The next session is tomorrow, 20th January! Check out k8s.dev/calendar, add the next session to your calendar and get started contributing!

#Kubernetes
Community Calendar
Meetings in the Kubernetes Community
k8s.dev
January 19, 2026 at 4:06 PM
Kubernetes v1.35: Restricting executables invoked by kubeconfigs via exec plugin allowList added to kuberc-
Kubernetes v1.35: Restricting executables invoked by kubeconfigs via exec plugin allowList added to kuberc
Did you know that kubectl can run arbitrary executables, including shell scripts, with the full privileges of the invoking user, and without your knowledge? Whenever you download or auto-generate a kubeconfig,...
kubernetes.io
January 12, 2026 at 4:06 PM
Kubernetes v1.35: Mutable PersistentVolume Node Affinity (alpha)-
Kubernetes v1.35: Mutable PersistentVolume Node Affinity (alpha)
The PersistentVolume node affinity API dates back to Kubernetes v1.10. It is widely used to express that volumes may not be equally accessible by all nodes in the cluster. This field was previously immutable,...
kubernetes.io
January 9, 2026 at 4:06 PM
Last Week in Kubernetes Development: Week Ending January 4, 2026 -
Week Ending January 4, 2026
Developer News
lwkd.info
January 8, 2026 at 8:52 PM
Kubernetes v1.35: A Better Way to Pass Service Account Tokens to CSI Drivers-
Kubernetes v1.35: A Better Way to Pass Service Account Tokens to CSI Drivers
If you maintain a CSI driver that uses service account tokens, Kubernetes v1.35 brings a refinement you'll want to know about. Since the introduction of the TokenRequests feature, service account tokens...
kubernetes.io
January 8, 2026 at 4:06 PM
Kubernetes v1.35: Extended Toleration Operators to Support Numeric Comparisons (Alpha)-
Kubernetes v1.35: Extended Toleration Operators to Support Numeric Comparisons (Alpha)
Many production Kubernetes clusters blend on-demand (higher-SLA) and spot/preemptible (lower-SLA) nodes to optimize costs while maintaining reliability for critical workloads. Platform teams need a safe...
kubernetes.io
January 6, 2026 at 4:06 PM