Skip to content

Commit ebc2858

Browse files
committed
CHANGELOG-3.6: Add entries for v3.6.9
Signed-off-by: Ivan Valdes <ivan@vald.es>
1 parent a01ae17 commit ebc2858

File tree

1 file changed

+9
-2
lines changed

1 file changed

+9
-2
lines changed

CHANGELOG/CHANGELOG-3.6.md

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,20 @@ Previous change logs can be found at [CHANGELOG-3.5](https://github.com/etcd-io/
44

55
---
66

7-
## v3.6.9 (TBC)
7+
## v3.6.10 (TBC)
8+
9+
---
10+
11+
## v3.6.9 (2026-03-20)
812

913
### etcd server
1014

1115
- [Ensure the metrics interceptor runs before other interceptors so that metrics remain up to date](https://github.com/etcd-io/etcd/pull/21329)
1216
- Fix [Race between read index and leader change](https://github.com/etcd-io/etcd/pull/21378)
1317
- Fix [Stale reads caused by process pausing](https://github.com/etcd-io/etcd/pull/21417)
1418
- Revert [Reuse events between sync loops](https://github.com/etcd-io/etcd/pull/21443)
19+
- Guard unauthenticated endpoints with auth checks to fix [Authorization bypasses in multiple APIs (CVE-2026-33413)](https://github.com/etcd-io/etcd/security/advisories/GHSA-q8m4-xhhv-38mg)
20+
- Enforce auth checks for nested txn ops to fix [Nested etcd transactions bypass RBAC authorization checks (CVE-2026-33343)](https://github.com/etcd-io/etcd/security/advisories/GHSA-rfx7-8w68-q57q)
1521

1622
### Package `clientv3`
1723

@@ -28,8 +34,9 @@ Previous change logs can be found at [CHANGELOG-3.5](https://github.com/etcd-io/
2834
### Dependencies
2935

3036
- [Bump go.opentelemetry.io/otel/sdk to v1.40.0 to resolve https://pkg.go.dev/vuln/GO-2026-4394](https://github.com/etcd-io/etcd/pull/21340)
31-
- Compile binaries using [go 1.25.7](https://github.com/etcd-io/etcd/pull/21393)
37+
- Compile binaries using [go 1.25.8](https://github.com/etcd-io/etcd/pull/21463)
3238
- [Bump golang.org/x/net to v0.51.0 to resolve GO-2026-4559](https://github.com/etcd-io/etcd/pull/21440)
39+
- [Bump google.golang.org/grpc to 1.79.3 to resolve CVE-2026-33186](https://github.com/etcd-io/etcd/pull/21501)
3340

3441
---
3542

0 commit comments

Comments
 (0)