Skip to content

fix(helm/cert-manager): update v1.20.1 ➼ v1.20.4 - #5418

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/cert-manager-1.20.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/cert-manager-1.20.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Apr 13, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
cert-manager (source) patch v1.20.1 → v1.20.4 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

cert-manager/cert-manager (cert-manager)

v1.20.4

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release updates Go and several dependencies to fix reported security vulnerabilities, and fixes a bug where ingress-shim removed the applyset label from cached Ingress and Gateway objects.

All users should upgrade.

[!NOTE]
Security scanners still report three golang.org/x/crypto findings. None of them affects cert-manager and we do not plan to fix them in the 1.20 line.

  • CVE-2026-56855 and CVE-2026-78662 are deadlocks in the golang.org/x/crypto/ssh connection multiplexer, triggered by a malicious SSH peer after a connection is established. cert-manager never opens an SSH connection. Only the controller links the ssh package, through vcert, which uses it to format a public key. The fix, golang.org/x/crypto v0.56.0, requires Go language version 1.26, which we will not adopt in a patch release. govulncheck confirms the vulnerable functions are not called.
  • GO-2026-5932 marks golang.org/x/crypto/openpgp as unmaintained. cert-manager does not import that package and there is no fixed version.

cert-manager 1.21 already uses golang.org/x/crypto v0.56.0, so upgrade to 1.21 if you need a clean scan.

Changes by Kind

Bug or Regression
  • Ingress-shim no longer removes the applyset label from cached Ingress and Gateway objects (#​9315, @​KR-Ravindra)
Other (Cleanup or Flake)

v1.20.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release fixes a security issue (GHSA-8rvj-mm4h-c258, HIGH) where the default cert-manager-edit aggregate ClusterRole granted namespace users permission to create ACME Challenge and Order resources directly. A user who could create a Challenge referencing a ClusterIssuer could supply attacker-controlled solver configuration while cert-manager loaded credentials from the ClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones, dnsNames, matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.

This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.

All users should upgrade.

[!WARNING]
Potentially breaking change: The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly.

Changes by Kind

Bug or Regression
Other (Cleanup or Flake)

v1.20.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.20.2 fixes invalid YAML generated in the Helm chart when both webhook.config
and webhook.volumes are defined, and bumps Go to 1.26.2 along with dependencies
to address reported vulnerabilities.

Changes by Kind

Bug or Regression
Other (Cleanup or Flake)

Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Apr 13, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 383c036
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Apr 13, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/tls/cert-manager/app Kustomization: flux-system/1-core-tls-cert-manager-app HelmRelease: cert-manager/cert-manager

+++ kube/deploy/core/tls/cert-manager/app Kustomization: flux-system/1-core-tls-cert-manager-app HelmRelease: cert-manager/cert-manager

@@ -13,13 +13,13 @@

     spec:
       chart: cert-manager
       sourceRef:
         kind: HelmRepository
         name: jetstack
         namespace: flux-system
-      version: v1.20.1
+      version: v1.20.3
   driftDetection:
     ignore:
     - paths:
       - /spec/replicas
     mode: warn
   install:

@tinfoild
tinfoild Bot force-pushed the renovate/cert-manager-1.20.x branch from 07ac7b0 to bc96cde Compare April 27, 2026 11:43
@tinfoild

tinfoild Bot commented Apr 27, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: cert-manager/cert-manager ClusterRole: cert-manager/cert-manager-edit

+++ HelmRelease: cert-manager/cert-manager ClusterRole: cert-manager/cert-manager-edit

@@ -31,14 +31,19 @@

   verbs:
   - update
 - apiGroups:
   - acme.cert-manager.io
   resources:
   - challenges
-  - orders
   verbs:
-  - create
   - delete
   - deletecollection
   - patch
   - update
+- apiGroups:
+  - acme.cert-manager.io
+  resources:
+  - orders
+  verbs:
+  - delete
+  - deletecollection
 
--- HelmRelease: cert-manager/cert-manager Deployment: cert-manager/cert-manager-cainjector

+++ HelmRelease: cert-manager/cert-manager Deployment: cert-manager/cert-manager-cainjector

@@ -31,13 +31,13 @@

       securityContext:
         runAsNonRoot: true
         seccompProfile:
           type: RuntimeDefault
       containers:
       - name: cert-manager-cainjector
-        image: quay.io/jetstack/cert-manager-cainjector:v1.20.1
+        image: quay.io/jetstack/cert-manager-cainjector:v1.20.4
         imagePullPolicy: IfNotPresent
         args:
         - --v=2
         - --leader-election-namespace=kube-system
         ports:
         - containerPort: 9402
--- HelmRelease: cert-manager/cert-manager Deployment: cert-manager/cert-manager

+++ HelmRelease: cert-manager/cert-manager Deployment: cert-manager/cert-manager

@@ -31,19 +31,19 @@

       securityContext:
         runAsNonRoot: true
         seccompProfile:
           type: RuntimeDefault
       containers:
       - name: cert-manager-controller
-        image: quay.io/jetstack/cert-manager-controller:v1.20.1
+        image: quay.io/jetstack/cert-manager-controller:v1.20.4
         imagePullPolicy: IfNotPresent
         args:
         - --v=2
         - --cluster-resource-namespace=
         - --leader-election-namespace=kube-system
-        - --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.20.1
+        - --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.20.4
         - --dns01-recursive-nameservers="https://1.0.0.1:443/dns-query","https://security.cloudflare-dns.com/dns-query","https://1.1.1.2:443/dns-query","https://1.0.0.2:443/dns-query","https://family.cloudflare-dns.com/dns-query","https://1.1.1.3:443/dns-query","https://1.0.0.3:443/dns-query"
         - --dns01-recursive-nameservers-only
         - --feature-gates=AdditionalCertificateOutputFormats=true
         - --max-concurrent-challenges=60
         ports:
         - containerPort: 9402
--- HelmRelease: cert-manager/cert-manager Deployment: cert-manager/cert-manager-webhook

+++ HelmRelease: cert-manager/cert-manager Deployment: cert-manager/cert-manager-webhook

@@ -31,13 +31,13 @@

       securityContext:
         runAsNonRoot: true
         seccompProfile:
           type: RuntimeDefault
       containers:
       - name: cert-manager-webhook
-        image: quay.io/jetstack/cert-manager-webhook:v1.20.1
+        image: quay.io/jetstack/cert-manager-webhook:v1.20.4
         imagePullPolicy: IfNotPresent
         args:
         - --v=2
         - --secure-port=10250
         - --dynamic-serving-ca-secret-namespace=
         - --dynamic-serving-ca-secret-name=cert-manager-webhook-ca
--- HelmRelease: cert-manager/cert-manager Job: cert-manager/cert-manager-startupapicheck

+++ HelmRelease: cert-manager/cert-manager Job: cert-manager/cert-manager-startupapicheck

@@ -31,13 +31,13 @@

       securityContext:
         runAsNonRoot: true
         seccompProfile:
           type: RuntimeDefault
       containers:
       - name: cert-manager-startupapicheck
-        image: quay.io/jetstack/cert-manager-startupapicheck:v1.20.1
+        image: quay.io/jetstack/cert-manager-startupapicheck:v1.20.4
         imagePullPolicy: IfNotPresent
         args:
         - check
         - api
         - --wait=1m
         - -v

@tinfoild
tinfoild Bot force-pushed the renovate/cert-manager-1.20.x branch from bc96cde to d12863f Compare May 15, 2026 18:38
@tinfoild
tinfoild Bot force-pushed the renovate/cert-manager-1.20.x branch from d12863f to 6f64969 Compare June 8, 2026 20:57
@tinfoild
tinfoild Bot force-pushed the renovate/cert-manager-1.20.x branch 2 times, most recently from 8644fe5 to 05f92a0 Compare June 25, 2026 15:04
@tinfoild tinfoild Bot changed the title fix(helm/cert-manager): update v1.20.1 ➼ v1.20.2 fix(helm/cert-manager): update v1.20.1 ➼ v1.20.3 Jun 25, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/cert-manager-1.20.x branch from 05f92a0 to ee3a19c Compare July 20, 2026 10:09
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 02:58 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5418 — fix(helm/cert-manager): update v1.20.1 ➼ v1.20.3
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 4


Severity Summary

Severity Count
CRITICAL 0
HIGH 2
MEDIUM / MODERATE 2
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 4

Results

Package: cert-manager

  • Ecosystem: Helm (Go binary — cert-manager/cert-manager)
  • Old version: v1.20.1 — VULNERABLE (1 confirmed, 3 needs-verification)
  • New version: v1.20.3 — CLEAN

Vulnerabilities in version v1.20.1

  1. GHSA-8rvj-mm4h-c258 / CVE-2026-62290 — Severity: HIGH (CVSS 7.3)

    • Description: Direct ACME Challenge resources can bypass Issuer DNS01 solver policy and use ClusterIssuer DNS credentials.
    • Affected versions: >= 1.18.0, <= 1.20.2
    • Fixed in: 1.19.6, 1.20.3
    • Sources: NVD, GHSA, Changelog
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-62290 | GHSA-8rvj-mm4h-c258
    • Status: ✅ Fixed in newer versions
  2. CVE-2026-42504 / GHSA-h524-452v-82p9 — Severity: HIGH

    • Description: Decoding maliciously-crafted MIME headers causes excessive CPU consumption (DoS). Go stdlib CVE fixed in Go 1.26.4.
    • Affected versions: Go < 1.26.4 (v1.20.1 ships with older Go)
    • Fixed in: Go 1.26.4 (used by v1.20.3)
    • Sources: GHSA, Changelog
    • Evidence: GHSA-h524-452v-82p9
    • Status: ⚠️ NEEDS VERIFICATION — Go stdlib CVE; actual exploitability in cert-manager context unclear
  3. CVE-2026-27145 / GHSA-4279-q6mj-392r — Severity: MEDIUM

    • Description: (*x509.Certificate).VerifyHostname — incomplete hostname validation in Go stdlib. Fixed in Go 1.26.4.
    • Affected versions: Go < 1.26.4 (v1.20.1 ships with older Go)
    • Fixed in: Go 1.26.4 (used by v1.20.3)
    • Sources: GHSA, Changelog
    • Evidence: GHSA-4279-q6mj-392r
    • Status: ⚠️ NEEDS VERIFICATION — Go stdlib CVE; actual exploitability in cert-manager context unclear
  4. CVE-2026-42507 / GHSA-h3gm-q7m7-mp28 — Severity: MEDIUM

    • Description: net/textproto error messages include user input, enabling log injection. Go stdlib CVE fixed in Go 1.26.4.
    • Affected versions: Go < 1.26.4 (v1.20.1 ships with older Go)
    • Fixed in: Go 1.26.4 (used by v1.20.3)
    • Sources: GHSA, Changelog
    • Evidence: GHSA-h3gm-q7m7-mp28
    • Status: ⚠️ NEEDS VERIFICATION — Go stdlib CVE; actual exploitability in cert-manager context unclear

Vulnerabilities in version v1.20.3

No known vulnerabilities found.

Non-applicable findings (verified and excluded)

Finding Severity Reason not applicable
CVE-2024-36537 HIGH Affects v1.14.4 only; both versions are >= 1.20.0
CVE-2024-12401 / GHSA-r4pg-vg54-wxx4 MEDIUM Fixed in 1.16.2; both v1.20.1 and v1.20.3 are past this fix
CVE-2026-25518 MEDIUM DNS-01 DoS, affects < 1.19.3; both versions are >= 1.20
CVE-2026-39350 MEDIUM Istio AuthorizationPolicy issue, not cert-manager
CVE-2026-10840 HIGH OpenShift Pipelines RBAC, not cert-manager directly
+37 more — Azure Linux / CleanStart distro trackers; all fixed in versions << 1.20.0

Changelog Security Highlights (v1.20.1 → v1.20.3)


Recommendations

  • MERGE PRIORITY: HIGH — The old version (v1.20.1) is directly vulnerable to GHSA-8rvj-mm4h-c258 (HIGH), which allows namespace users to bypass ClusterIssuer DNS01 solver selectors and potentially disclose DNS credentials to attacker-controlled endpoints. This is fully remediated in v1.20.3.
  • Three Go stdlib CVEs (CVE-2026-27145, CVE-2026-42504, CVE-2026-42507) are also patched via the Go 1.26.4 rebuild in v1.20.3, though their exploitability in cert-manager's runtime context has not been verified.
  • ⚠️ Potential breaking change: The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create|patch|update for orders.acme.cert-manager.io. Verify custom tooling/workflows before deploying this update.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild
tinfoild Bot force-pushed the renovate/cert-manager-1.20.x branch from ee3a19c to 383c036 Compare September 16, 2026 20:19
@tinfoild tinfoild Bot changed the title fix(helm/cert-manager): update v1.20.1 ➼ v1.20.3 fix(helm/cert-manager): update v1.20.1 ➼ v1.20.4 Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant