CVE-2026-40356

Releases whose notes mention this CVE, found verbatim in the text — 5 releases so far. The vulnerability itself is described in the National Vulnerability Database. Or browse all security updates.

Releases mentioning CVE-2026-40356

Redpanda

Redpanda Data · Databases & Data

Changes to cloudstoragethroughputlimitpercent cluster config now take effect at runtime instead of being ignored until restart; Fix consumer group lag metrics inflated after…

FixedSecurity

Redpanda

Redpanda Data · Databases & Data

Redpanda Enterprise now supports major version rollback via unfinalized upgrades with rpk cluster upgrade finalize and rpk cluster upgrade status commands; Shadowing from…

Added

Redpanda

Redpanda Data · Databases & Data

rpk --print-tree emits the full rpk command tree as a single JSON document, suited for LLMs and automations; Fix consumer group lag metrics inflated after retention or…

AddedChangedFixedSecurity

Redpanda

Redpanda Data · Databases & Data

New live-reloadable cluster configs oidchttpproxyusername and oidchttpproxypassword add HTTP Basic authentication to the OIDC forward proxy; New cluster property…

AddedChangedFixedSecurity

Redpanda

Redpanda Data · Databases & Data

Add OAUTHBEARER SASL mechanism support to rpk, enabling OIDC-based authentication for the Kafka client, admin API, and schema registry via --password and --sasl-mechanism…

AddedChangedFixedSecurity