Skip to content

Commit a01ae17

Browse files
committed
CHANGELOG-3.5: Add entries for v3.5.28
Signed-off-by: Ivan Valdes <ivan@vald.es>
1 parent f9c0c0d commit a01ae17

File tree

1 file changed

+10
-2
lines changed

1 file changed

+10
-2
lines changed

CHANGELOG/CHANGELOG-3.5.md

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,20 @@ Previous change logs can be found at [CHANGELOG-3.4](https://github.com/etcd-io/
44

55
---
66

7-
## v3.5.28 (TBC)
7+
## v3.5.29 (TBC)
8+
9+
---
10+
11+
## v3.5.28 (2026-03-20)
812

913
### etcd server
1014

1115
- [Ensure the metrics interceptor runs before other interceptors so that metrics remain up to date](https://github.com/etcd-io/etcd/pull/21336)
1216
- Fix [Race between read index and leader change](https://github.com/etcd-io/etcd/pull/21387)
1317
- Fix [Stale reads caused by process pausing](https://github.com/etcd-io/etcd/pull/21421)
18+
- Fix [cannot promote member from follower when auth is enabled](https://github.com/etcd-io/etcd/pull/21494)
19+
- Guard unauthenticated endpoints with auth checks to fix [Authorization bypasses in multiple APIs (CVE-2026-33413)](https://github.com/etcd-io/etcd/security/advisories/GHSA-q8m4-xhhv-38mg)
20+
- Enforce auth checks for nested txn ops to fix [Nested etcd transactions bypass RBAC authorization checks (CVE-2026-33343)](https://github.com/etcd-io/etcd/security/advisories/GHSA-rfx7-8w68-q57q)
1421

1522
### Package `clientv3`
1623

@@ -27,8 +34,9 @@ Previous change logs can be found at [CHANGELOG-3.4](https://github.com/etcd-io/
2734
### Dependencies
2835

2936
- [Bump go.opentelemetry.io/otel/sdk to v1.40.0 to resolve https://pkg.go.dev/vuln/GO-2026-4394](https://github.com/etcd-io/etcd/pull/21338)
30-
- Compile binaries using [go 1.25.7](https://github.com/etcd-io/etcd/pull/21405)
37+
- Compile binaries using [go 1.25.8](https://github.com/etcd-io/etcd/pull/21462)
3138
- [Bump golang.org/x/net to v0.51.0 to resolve GO-2026-4559](https://github.com/etcd-io/etcd/pull/21441)
39+
- [Bump google.golang.org/grpc to 1.79.3 to resolve CVE-2026-33186](https://github.com/etcd-io/etcd/pull/21500)
3240

3341
---
3442

0 commit comments

Comments
 (0)