29 Aug 2026 #### Bug fixes - Fixes a panic in kube-controllers when the informer delivers a tombstone object to a delete handler. [calico 13631](https://github.com/projectcalico/calico/pull/13631) (@hjiawei) - Fix VXLAN traffic being dropped when the kernel masqueraded a tunnel flow's source port onto the VXLAN port (default 4789). [calico 13628](https://github.com/projectcalico/calico/pull/13628) (@hengqiali) - Fixed two eBPF dataplane service affinity bugs: consecutive datagrams from an unconnected UDP socket could be sent to different backends because Felix's affinity map cleanup deleted the connect-time load balancer's affinity entries; and a UDP service using sessionAffinity had its affinity timeout capped at the much shorter BPF UDP conntrack timeout on the connect-time load balancer path. Also fixed session affinity never working for a LoadBalancer or ExternalIP service that sets loadBalancerSourceRanges. [calico 13606](https://github.com/projectcalico/calico/pull/13606) (@tomastigera) - Fix that Felix kept re-emitting stale deny flow logs with zero counters (shown in Whisker as a live deny) after a policy change allowed the traffic. [calico 13573](https://github.com/projectcalico/calico/pull/13573) (@radTuti) - Fixed OpenStack DHCP agent handling of subnet CIDR re-use. Previously, when a network was deleted and a new network was created re-using the same subnet CIDR, the new network's VMs could fail to get DHCP responses, and DHCP updates for other networks on the same host could be delayed by several minutes. Also fixed the underlying etcd watch issue, which could delay the DHCP agent's response to any port or subnet change by around 10 seconds. [calico 13487](https://github.com/projectcalico/calico/pull/13487) (@nelljerram) - Fixed a case where the OpenStack DHCP agent could serve stale subnet data (e.g. outdated gateway or DNS options) indefinitely, if a subnet deletion coincided with an etcd watch restart and an overlapping subnet was later created in the same network. [calico 13487](https://github.com/projectcalico/calico/pull/13487) (@nelljerram) - Fix IPv6 route programming during VM live migration: IPv6 workload routes are now suppressed on the migration target until the VM goes live, and elevated in priority after cutover, as was already the case for IPv4. Previously IPv6 traffic to a migrating VM could black-hole for the duration of the migration on dual-stack clusters. [calico 13481](https://github.com/projectcalico/calico/pull/13481) (@nelljerram) - Fixes a bug where cancelling a datastore migration on a cluster that had already been migrated would delete the migrated Calico configuration. [calico 13475](https://github.com/projectcalico/calico/pull/13475) (@caseydavenport) - ebpf: Fixed IPv6 session affinity entries being randomly deleted (or never expiring) due to a struct layout mismatch when Felix read the affinity timestamp, which could re-balance sticky connections to a different backend. [calico 13459](https://github.com/projectcalico/calico/pull/13459) (@tomastigera) - Fixes an issue where an IP pool could be left without its Allocatable status condition, causing IPAM to keep allocating from a disabled or overlapping pool in some setups. [calico 13448](https://github.com/projectcalico/calico/pull/13448) (@caseydavenport) - HELM: Fix installation of the projectcalico.org.v3 CRDs chart on Kubernetes 1.36+ by rendering the MutatingAdmissionPolicy resources at the API version the cluster actually serves. [calico 13447](https://github.com/projectcalico/calico/pull/13447) (@caseydavenport) - Fixes spurious `unknown field "status"` warnings logged when kube-controllers manages tier finalizers. [calico 13446](https://github.com/projectcalico/calico/pull/13446) (@caseydavenport) - Fixes an issue in nftables mode where IP set members could be left unprogrammed after the nftables table was deleted and recreated. [calico 13445](https://github.com/projectcalico/calico/pull/13445) (@caseydavenport) - Fixes an issue in nftables mode where Felix could panic when reading back an IP set member it could not parse. [calico 13445](https://github.com/projectcalico/calico/pull/13445) (@caseydavenport) - Fixes an issue where IP sets containing overlapping CIDRs could fail to program correctly in nftables mode after a member was removed. [calico 13444](https://github.com/projectcalico/calico/pull/13444) (@caseydavenport) - Fixes a loss of connectivity to a node when its host IP falls within a Calico IPAM block, in setups where the node network overlaps a Calico IP pool. [calico 13443](https://github.com/projectcalico/calico/pull/13443) (@caseydavenport) - Fixes CALICO_IPV6POOL_VXLAN being ignored in IPv6-only clusters where the IPv4 pool is disabled (CALICO_IPV4POOL_CIDR=none), which left the IPv6 pool without VXLAN encapsulation. [calico 13440](https://github.com/projectcalico/calico/pull/13440) (@caseydavenport) - [eBPF] Fix a window in which a new connection to a local workload could skip that workload's ingress policy, when the connection was started while the workload's route was still being programmed. [calico 13389](https://github.com/projectcalico/calico/pull/13389) (@tomastigera) - Fixed a stalled-connection bug in the eBPF dataplane where a client pod could not exchange data with a VM workload on the same node, because established-flow packets bypassed the destination MAC rewrite. [calico 13386](https://github.com/projectcalico/calico/pull/13386) (@fasaxc) - Fixed the bundled Envoy Gateway crash-looping on clusters whose Gateway API CRD set omits ListenerSet, TLSRoute or BackendTLSPolicy, such as OpenShift or GKE's managed Gateway API addon. [calico 13366](https://github.com/projectcalico/calico/pull/13366) (@electricjesus) - Fixes an "unrecognized format" warning printed by Kubernetes 1.36 when applying the IPReservation CRD. [calico 13342](https://github.com/projectcalico/calico/pull/13342) (@caseydavenport) - Raises the Calico webhooks server's Kubernetes client rate limits so that bursts of policy changes are no longer delayed by client-side throttling. [calico 13312](https://github.com/projectcalico/calico/pull/13312) (@caseydavenport) - Fix that the networking-calico periodic resync could transiently delete the destination WorkloadEndpoint of an in-flight live migration, disrupting the migrated VM's connectivity. [calico 13285](https://github.com/projectcalico/calico/pull/13285) (@nelljerram) - Fixed a regression in the eBPF dataplane where ordinary pod egress carried the ext-to-service connmark into the FIB lookup, breaking cross-node connectivity (including DNS) on nodes that use source-based routing such as AWS VPC CNI. [calico 13260](https://github.com/projectcalico/calico/pull/13260) (@tomastigera) - Fixed a bug where Calico could advertise a Service IP over BGP from a node whose local endpoint was not Ready, causing connection failures. [calico 13253](https://github.com/projectcalico/calico/pull/13253) (@MichalFupso) - Fixed a kernel dmesg spew ("could not enable bpf_trace_printk events") on eBPF-dataplane nodes running with kernel lockdown=confidentiality (e.g. Talos). [calico 13232](https://github.com/projectcalico/calico/pull/13232) (@tomastigera) - Fixed a rare start-of-day deadlock that could prevent Felix from restarting when a restart-requiring configuration change (e.g. the node IP being set) arrived while Felix was still starting up. [calico 13214](https://github.com/projectcalico/calico/pull/13214) (@fasaxc) - Fixed a latent bug where EnsureBlock could allocate an IPv6 block from the wrong IP pool when an explicit IPv6 pool selector was provided (Windows host-local IPAM block reservation). [calico 13214](https://github.com/projectcalico/calico/pull/13214) (@fasaxc) - eBPF: fix state explosion in the BPF verifier (resulting in programs not loading) caused by debug logs on a certain path. [calico 13214](https://github.com/projectcalico/calico/pull/13214) (@fasaxc) - Bugfix: fix BIRD config generation on Windows, following some recent confd refactoring. [calico 13163](https://github.com/projectcalico/calico/pull/13163) (@nelljerram) - Fixed a Felix dataplane deadlock that could be triggered when a gratuitous ARP / RARP from a live-migrated VM raced with the migration-complete update from the datastore. [calico 13163](https://github.com/projectcalico/calico/pull/13163) (@nelljerram) - Bugfix for OpenStack: Set the host-side MAC address in the same way as libvirt used (< 9.5.0) to do for Nova-plugged TAP interfaces, but now does not (because of those interfaces having to be marked as `managed=no`). This allows for live migration from a hypervisor with libvirt<9.5.0 to one with libvirt>=9.5.0. [calico 13163](https://github.com/projectcalico/calico/pull/13163) (@nelljerram) - Fixed a regression in eBPF mode where traffic on the WireGuard port (51820 by default) arriving at a host interface was dropped unless it came from a known Calico node, breaking user-managed WireGuard overlays and Calico WireGuard between nodes with differing underlay addresses (e.g. behind NAT). [calico 13137](https://github.com/projectcalico/calico/pull/13137) (@tomastigera) - eBPF dataplane: fix loss of connectivity to the Kubernetes API server service after the API server is unavailable for a period, when using bpfNetworkBootstrap. Felix no longer clears the API server service's NAT backend when its endpoints transiently empty, so connectivity recovers without a calico-node restart. [calico 13091](https://github.com/projectcalico/calico/pull/13091) (@lucastigera) #### Other changes - Resolve Go standard-library CVEs in the flannel-migration-controller image by replacing the bundled kubectl binary with the k8s.io/kubectl library. [calico 13657](https://github.com/projectcalico/calico/pull/13657) (@skoryk-oleksandr) - Update the react-router-dom dependency in the Whisker UI to 6.30.6 to resolve CVE-2026-53668. [calico 13654](https://github.com/projectcalico/calico/pull/13654) (@skoryk-oleksandr) - Refresh the node-driver-registrar dependency patch to remediate CVEs (grpc v1.82.1, x/net, x/text). [calico 13527](https://github.com/projectcalico/calico/pull/13527) (@skoryk-oleksandr) - Bump cel-go (v0.29.2) and OpenTelemetry (v1.44.0) to remediate CVEs on the calico images. [calico 13525](https://github.com/projectcalico/calico/pull/13525) (@skoryk-oleksandr) - Update bundled Envoy Gateway to v1.8.3 to remediate CVEs. [calico 13523](https://github.com/projectcalico/calico/pull/13523) (@skoryk-oleksandr) - Update bundled Istio to 1.29.6 and refresh its dependency patch (grpc v1.82.1) to remediate CVEs. [calico 13505](https://github.com/projectcalico/calico/pull/13505) (@skoryk-oleksandr) - Update bundled envoy-proxy image (v1.38.3) and refresh envoy-ratelimit dependency patch to remediate CVEs. [calico 13503](https://github.com/projectcalico/calico/pull/13503) (@skoryk-oleksandr) - The DatastoreMigration CRD is now published to the release manifests directory, so it can be installed with `kubectl apply -f .../manifests/migration.projectcalico.org_datastoremigrations.yaml` instead of a path into the source tree. [calico 13393](https://github.com/projectcalico/calico/pull/13393) (@caseydavenport) - calicoctl is now available as a Debian/Ubuntu and RPM package from the Calico package repositories. [calico 13387](https://github.com/projectcalico/calico/pull/13387) (@nelljerram) - The default CNI configuration now declares cniVersion 1.0.0 (previously 0.3.1), enabling Calico as a multus delegate on OpenShift 4.23+. Requires containerd v1.6+ or CRI-O v1.24+. [calico 13379](https://github.com/projectcalico/calico/pull/13379) (@sridhartigera) - Adds a calicoctl datastore migrate-policy-names command to fix pre-v3.32 policy names on an etcdv3 datastore that was upgraded in place. [calico 13288](https://github.com/projectcalico/calico/pull/13288) (@nelljerram) - Felix/Dikastes performance: reduce CPU and GC load generated by the user-mode policy engine. 4x improvement for large policy sets. [calico 13286](https://github.com/projectcalico/calico/pull/13286) (@fasaxc) - Felix: periodic IP set resyncs are now incremental, avoiding dataplane stalls on nodes with many IP sets. [calico 13250](https://github.com/projectcalico/calico/pull/13250) (@fasaxc)