<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:apigee-hybrid-release-notes</id>
  <title>Apigee hybrid - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/apigee-hybrid-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-08-11T00:00:00-07:00</updated>

  <entry>
    <title>August 11, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#August_11_2026</id>
    <updated>2026-08-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#August_11_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.9</strong>
<h3>Announcement</h3>
<h3 id="v1169">v1.16.9</h3>
<p>On August 11, 2026 we released an updated version of the Apigee hybrid software, v1.16.9.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.9</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>514973778</strong></td>
<td><strong>Fixed an issue where the <code>SanitizeUserPrompt</code> and <code>SanitizeModelResponse</code> policies failed to tolerate unknown fields while parsing responses from the Model Armor Service.</strong></td>
</tr>
<tr>
<td><strong>543171828</strong></td>
<td><strong>Fixed an issue where the <code>apigee-logger</code> DaemonSet failed to schedule on cluster nodes without custom node labels due to a default <code>logger.nodeSelector</code> in the Helm chart.</strong></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 31, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#July_31_2026</id>
    <updated>2026-07-31T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#July_31_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.15.7</strong>
<h3>Announcement</h3>
<h3 id="v1157">v1.15.7</h3>
<p>On July 31, 2026 we released an updated version of the Apigee hybrid software, v1.15.7.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.7</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Runtime rollout strategy configuration</strong></p>
<p>In this release, you can configure the rollout strategy used when updating runtime (message processor) ReplicaSets by setting the <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#runtime-release-strategy"><code>runtime.release.strategy</code></a> property (with options <code>rolling</code>, <code>scale-down-first</code>, or <code>none</code>) or per-environment with <code>envs[].components.runtime.release.strategy</code> in your overrides configuration file. The property defaults to <code>rolling</code>.</p>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 24, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#July_24_2026</id>
    <updated>2026-07-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#July_24_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.8</strong>
<h3>Announcement</h3>
<h3 id="v1168">v1.16.8</h3>
<p>On July 24, 2026 we released an updated version of the Apigee hybrid software, v1.16.8.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version 1.16</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release_2">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>493354568</strong></td>
<td><strong>Fixed an issue where component-specific nodeSelector configurations are ignored in Helm charts.</strong></td>
</tr>
</tbody>
</table>
<h3>Feature</h3>
<p><strong>Runtime rollout strategy configuration</strong></p>
<p>In this release, you can configure the rollout strategy used when updating runtime (message processor) ReplicaSets by setting the <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/config-prop-ref#runtime-release-strategy"><code>runtime.release.strategy</code></a> property (with options <code>rolling</code>, <code>scale-down-first</code>, or <code>none</code>) or per-environment with <code>envs[].components.runtime.release.strategy</code> in your overrides configuration file. The property defaults to <code>rolling</code>.</p>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 23, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#July_23_2026</id>
    <updated>2026-07-23T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#July_23_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.14.7</strong>
<h3>Announcement</h3>
<h3 id="v1147">v1.14.7</h3>
<p>On July 23, 2026 we released an updated version of the Apigee hybrid software, v1.14.7.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version 1.14</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Runtime rollout strategy configuration</strong></p>
<p>In this release, you can configure the rollout strategy used when updating runtime (message processor) ReplicaSets by setting the <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/config-prop-ref#runtime-release-strategy"><code>runtime.release.strategy</code></a> property (with options <code>rolling</code>, <code>scale-down-first</code>, or <code>none</code>) or per-environment with <code>envs[].components.runtime.release.strategy</code> in your overrides configuration file. The property defaults to <code>rolling</code>.</p>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 15, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#July_15_2026</id>
    <updated>2026-07-15T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#July_15_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.15.6</strong>
<h3>Announcement</h3>
<h3 id="v1156">v1.15.6</h3>
<p>On July 15, 2026 we released an updated version of the Apigee hybrid software, v1.15.6.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.6</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 10, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#July_10_2026</id>
    <updated>2026-07-10T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#July_10_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.7</strong>
<h3>Announcement</h3>
<h3 id="v1167">v1.16.7</h3>
<p>On July 10, 2026 we released an updated version of the Apigee hybrid software, v1.16.7.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.7</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 03, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#July_03_2026</id>
    <updated>2026-07-03T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#July_03_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.15.5</strong>
<h3>Announcement</h3>
<h3 id="v1155">v1.15.5</h3>
<p>On July 3, 2026 we released an updated version of the Apigee hybrid software, v1.15.5.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.5</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 19, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#June_19_2026</id>
    <updated>2026-06-19T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#June_19_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.6</strong>
<h3>Announcement</h3>
<h3 id="v1166">v1.16.6</h3>
<p>On June 19, 2026 we released an updated version of the Apigee hybrid software, v1.16.6.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.6</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>HAProxy PROXY-protocol support on Apigee ingress gateway</strong></p>
<p>In this release, you can opt into HAProxy PROXY-protocol parsing by setting the <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/config-prop-ref#ingressgateways-proxyprotocol-mode"><code>ingressGateways[].proxyProtocol.mode</code></a> property (with options <code>strict</code>, <code>permissive</code>, or <code>disable</code>) in your overrides configuration file. The property defaults to <code>disable</code>.</p>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 16, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#June_16_2026</id>
    <updated>2026-06-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#June_16_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.14.6</strong>
<h3>Announcement</h3>
<h3 id="v1146">v1.14.6</h3>
<p>On June 16, 2026 we released an updated version of the Apigee hybrid software, v1.14.6.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version v1.14.6</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 08, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#June_08_2026</id>
    <updated>2026-06-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#June_08_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.5</strong>
<h3>Announcement</h3>
<h3 id="v1165">v1.16.5</h3>
<p>On June 8, 2026 we released an updated version of the Apigee hybrid software, v1.16.5.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.5</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 30, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#May_30_2026</id>
    <updated>2026-05-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#May_30_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.15.4</strong>
<h3>Announcement</h3>
<h3 id="v1154">v1.15.4</h3>
<p>On May 30, 2026 we released an updated version of the Apigee hybrid software, v1.15.4.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.4</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 22, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#May_22_2026</id>
    <updated>2026-05-22T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#May_22_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.14.5</strong>
<h3>Announcement</h3>
<h3 id="v1145">v1.14.5</h3>
<p>On May 22, 2026 we released an updated version of the Apigee hybrid software, v1.14.5.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version v1.14.5</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<strong class="release-note-product-version-title">v1.16.0</strong>
<h3>Announcement</h3>
<p>On May 22, 2026 we released an updated version of the Apigee UI.</p>
<p>The <b>Management <span aria-label="and then">&gt;</span> Instances</b> page now displays Apigee hybrid instances. The display includes the instance name, location, and runtime version.</p>
<p>See <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/instances">Managing instances</a>.</p>
<h3>Announcement</h3>
<h3 id="apigee_emulator_is_now_released_independently">Apigee Emulator is now released independently</h3>
<p>Starting May 22, 2026, the Apigee Emulator is versioned and released
independently from Apigee hybrid. Emulator updates, including security patches,
are no longer tied to hybrid release cycles.</p>
<p>The emulator image continues to be available at
<code>gcr.io/apigee-release/hybrid/apigee-emulator</code>. The first independent release
is <strong>v2.0.0</strong>.</p>
<p>For emulator release notes going forward, see
<a href="https://docs.cloud.google.com/apigee/docs/release/release-notes">Apigee release notes</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 21, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#May_21_2026</id>
    <updated>2026-05-21T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#May_21_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.4</strong>
<h3>Announcement</h3>
<h3 id="v1164">v1.16.4</h3>
<p>On May 21, 2026 we released an updated version of the Apigee hybrid software, v1.16.4.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.4</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>515424331</strong></td>
<td><strong>Fixed an issue with missing container images in the <code>gcr.io/apigee-release/hybrid/</code> repository.</strong></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>May 19, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#May_19_2026</id>
    <updated>2026-05-19T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#May_19_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.3</strong>
<h3>Announcement</h3>
<h3 id="v1163">v1.16.3</h3>
<p>On May 19, 2026 we released an updated version of the Apigee hybrid software, v1.16.3.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.3</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release_2">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>512866352</strong></td>
<td><strong>Fixed an issue where the <code>apigee-redis</code> pod entered a <code>CrashLoopBackOff</code> state when deployed with Vault-based secret injection due to a GLIBC version mismatch in the bundled <code>/bin/sh</code> and <code>/bin/cat</code> binaries.</strong></td>
</tr>
</tbody>
</table>
<h3>Feature</h3>
<p><strong>Custom environment variables for Guardrail pods (<code>guardrails.envVars</code>)</strong></p>
<p>Starting in version v1.16.3, you can inject custom environment variables into Apigee hybrid Guardrail pods using the new <code>guardrails.envVars</code> property in <code>overrides.yaml</code>. This is most commonly used to set <code>NO_PROXY</code> (or <code>no_proxy</code>) so that Guardrail pods bypass a configured forward HTTP proxy when calling internal in-cluster endpoints such as the Kubernetes API server, which previously failed in restricted-network environments with a global <code>httpProxy</code> configured. The property is supported on Guardrail pods for the following components: <code>apigee-datastore</code>, <code>apigee-env</code>, <code>apigee-ingress-manager</code>, <code>apigee-operator</code>, <code>apigee-org</code>, <code>apigee-redis</code>, <code>apigee-telemetry</code>, and <code>apigee-virtualhost</code>.</p>
<p>Example:</p>
<pre class="prettyprint lang-yaml"><code>guardrails:
  envVars:
    NO_PROXY: 'kubernetes.default.svc,172.20.0.1'
</code></pre>
]]>
    </content>
  </entry>

  <entry>
    <title>May 13, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#May_13_2026</id>
    <updated>2026-05-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#May_13_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.2</strong>
<h3>Announcement</h3>
<h3 id="v1162">v1.16.2</h3>
<p>On May 13, 2026 we released an updated version of the Apigee hybrid software, v1.16.2.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.2</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Basic Auth credential support for forward proxies</strong></p>
<p>Starting in version v1.16.2, Apigee hybrid runtime components can accept credentials for an upstream forward proxy that enforces HTTP Basic Auth. You can now configure a Basic Auth username and password for the forward proxy in your overrides.yaml. This resolves known issue tracked in b/499322601. See <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/forward-proxy">Configure Apigee hybrid to use a forward proxy</a>.</p>
<h3>Feature</h3>
<p><strong>Sidecar authentication for Workload Identity Federation on AKS and EKS</strong></p>
<p>Starting in version v1.16.2, you can now use a sidecar along with Workload Identity Federation on AKS and EKS to mount security tokens from your preferred identity provider (IDP) for service account authentication. This method is an alternative to using Kubernetes Projected Service Account Tokens, and is useful when you need to integrate with a custom Identity Provider. See <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/use-sidecar-for-wif">Use sidecar authentication for Workload Identity Federation on AKS and EKS</a>.</p>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release_3">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>485738013</strong></td>
<td><strong>Fixed an issue where API products with <code>LLMTokenQuota</code> operations were not enforcing model-based access restrictions, allowing requests to models not listed in the product to bypass the operations check.</strong></td>
</tr>
<tr>
<td><strong>479288727</strong></td>
<td><strong>Fixed an issue where the Apigee UI and API reported a 10+ minute delay in deployment status after performing a proxy deployment.</strong></td>
</tr>
<tr>
<td><strong>499223890</strong></td>
<td><strong>Fixed an issue where the runtime could not handle HTTP proxy passwords containing special characters in Apigee hybrid 1.16.0-hotfix-1 configurations.</strong></td>
</tr>
<tr>
<td><strong>500861814</strong></td>
<td><strong>Fixed an issue that caused excessive Message Processor (MP) upscaling and failure to downscale.</strong></td>
</tr>
<tr>
<td><strong>510438578</strong></td>
<td><strong>Fixed an ingestion-blocking issue with <code>apigee-stackdriver-prometheus-sidecar</code> in Apigee hybrid 1.16.1.</strong></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 04, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#May_04_2026</id>
    <updated>2026-05-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#May_04_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.15.3</strong>
<h3>Announcement</h3>
<h3 id="v1153">v1.15.3</h3>
<p>On May 4, 2026 we released an updated version of the Apigee hybrid software, v1.15.3.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.3</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33997">CVE-2026-33997</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0915">CVE-2026-0915</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0861">CVE-2026-0861</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15281">CVE-2025-15281</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35469">CVE-2026-35469</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33997">CVE-2026-33997</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-connect-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31789">CVE-2026-31789</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28387">CVE-2026-28387</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39883">CVE-2026-39883</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">CVE-2026-34480</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">CVE-2026-34478</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48913">CVE-2025-48913</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mint-task-scheduler</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">CVE-2026-34480</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">CVE-2026-34478</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prom-prometheus</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39883">CVE-2026-39883</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">CVE-2026-34480</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">CVE-2026-34478</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48913">CVE-2025-48913</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41316">CVE-2026-41316</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35611">CVE-2026-35611</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33210">CVE-2026-33210</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33176">CVE-2026-33176</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">CVE-2026-34480</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">CVE-2026-34478</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48913">CVE-2025-48913</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39883">CVE-2026-39883</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34986">CVE-2026-34986</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29181">CVE-2026-29181</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35469">CVE-2026-35469</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>April 27, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#April_27_2026</id>
    <updated>2026-04-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#April_27_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.14.4</strong>
<h3>Announcement</h3>
<h3 id="v1144">v1.14.4</h3>
<p>On April 27, 2026 we released an updated version of the Apigee hybrid software, v1.14.4.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version v1.14.4</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Sidecar authentication for Workload Identity Federation on non-GKE platforms</strong></p>
<p>Starting in version v1.14.4, you can now use a sidecar along with Workload Identity Federation on non-GKE platforms to mount security tokens from your preferred identity provider (IDP) for service account authentication. See <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/use-sidecar-for-wif">Use sidecar authentication for Workload Identity Federation on non-GKE platforms</a>.</p>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>471527485, 471173296, 471172082, 471171833</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056">CVE-2025-58056</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li></ul></td>
</tr>
<tr>
<td><strong>471290390, 471199955, 471197958, 470990914</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056">CVE-2025-58056</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li></ul></td>
</tr>
<tr>
<td><strong>470992132, 470991089, 470989623, 470989232, 470988977</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056">CVE-2025-58056</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li></ul></td>
</tr>
<tr>
<td><strong>470953507, 470953254, 470952893</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40897">CVE-2022-40897</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2976">CVE-2023-2976</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47273">CVE-2025-47273</a> </li></ul></td>
</tr>
<tr>
<td><strong>451224723, 451224123</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4756">CVE-2010-4756</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3389">CVE-2011-3389</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4392">CVE-2013-4392</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3276">CVE-2015-3276</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14159">CVE-2017-14159</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17740">CVE-2017-17740</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20796">CVE-2018-20796</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5709">CVE-2018-5709</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6829">CVE-2018-6829</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010022">CVE-2019-1010022</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010023">CVE-2019-1010023</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010024">CVE-2019-1010024</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010025">CVE-2019-1010025</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9192">CVE-2019-9192</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15719">CVE-2020-15719</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27943">CVE-2022-27943</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2953">CVE-2023-2953</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31437">CVE-2023-31437</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31438">CVE-2023-31438</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31439">CVE-2023-31439</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45853">CVE-2023-45853</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2236">CVE-2024-2236</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2379">CVE-2024-2379</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26458">CVE-2024-26458</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26461">CVE-2024-26461</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0725">CVE-2025-0725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10148">CVE-2025-10148</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27587">CVE-2025-27587</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62813">CVE-2025-62813</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9086">CVE-2025-9086</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9230">CVE-2025-9230</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9232">CVE-2025-9232</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4437">CVE-2026-4437</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4046">CVE-2026-4046</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-connect-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68121">CVE-2025-68121</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-envoy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4437">CVE-2026-4437</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4046">CVE-2026-4046</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mint-task-scheduler</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33871">CVE-2026-33871</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33870">CVE-2026-33870</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32287">CVE-2026-32287</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prom-prometheus</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32023">CVE-2025-32023</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33176">CVE-2026-33176</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61594">CVE-2025-61594</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24294">CVE-2025-24294</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33953">CVE-2023-33953</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32511">CVE-2022-32511</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29181">CVE-2022-29181</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24839">CVE-2022-24839</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24836">CVE-2022-24836</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0759">CVE-2022-0759</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41817">CVE-2021-41817</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31799">CVE-2021-31799</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30560">CVE-2021-30560</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28965">CVE-2021-28965</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23214">CVE-2021-23214</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25695">CVE-2020-25695</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25694">CVE-2020-25694</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25613">CVE-2020-25613</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3881">CVE-2019-3881</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25032">CVE-2018-25032</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1115">CVE-2018-1115</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10915">CVE-2018-10915</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1058">CVE-2018-1058</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1053">CVE-2018-1053</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7546">CVE-2017-7546</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7484">CVE-2017-7484</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15098">CVE-2017-15098</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14798">CVE-2017-14798</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7954">CVE-2016-7954</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7048">CVE-2016-7048</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5424">CVE-2016-5424</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5423">CVE-2016-5423</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0766">CVE-2016-0766</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3167">CVE-2015-3167</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3166">CVE-2015-3166</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0244">CVE-2015-0244</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0243">CVE-2015-0243</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0241">CVE-2015-0241</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li></ul></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>April 20, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#April_20_2026</id>
    <updated>2026-04-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#April_20_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.1</strong>
<h3>Announcement</h3>
<h3 id="v1161">v1.16.1</h3>
<p>On April 20, 2026 we released an updated version of the Apigee hybrid software, v1.16.1.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.1</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release_4">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>469900037</strong></td>
<td><strong>Apigee hybrid now supports <code>LLMTokenQuota</code> and <code>PromptTokenLimit</code> policies.</strong></td>
</tr>
<tr>
<td><strong>502577947</strong></td>
<td><strong>Enhanced the <code>ParsePayload</code> policy to support a broader set of Model Context Protocol (MCP) methods and implemented governance bypass for essential system-level methods.</strong></td>
</tr>
<tr>
<td><strong>503029410</strong></td>
<td><strong>Removed PII from <code>ParsePayload</code> policy outputs to improve security and privacy.</strong></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>485998102, 482978613</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>, <code>apigee-mart-server</code>, and <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21945">CVE-2026-21945</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2976">CVE-2023-2976</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48174">CVE-2022-48174</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1471">CVE-2022-1471</a> </li></ul></td>
</tr>
<tr>
<td><strong>471527485, 471173296, 471172082, 471171833</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056">CVE-2025-58056</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li></ul></td>
</tr>
<tr>
<td><strong>454672970</strong></td>
<td><strong>Security fix for <code>apigee-runtime</code>.</strong> <br/>This adds strict input validation to the <code>IntegrationRegion</code> parameter in the <code>SetIntegrationRequest</code> policy to prevent potential server-side request forgery (SSRF).</td>
</tr>
<tr>
<td><strong>493067053, 493061344, 492959383, 492957334, 492359443, 492358696, 492067139, 490280970, 489908390, 489907729, 489489437, 488070159, 485580973</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66566">CVE-2025-66566</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4802">CVE-2025-4802</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12183">CVE-2025-12183</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6246">CVE-2023-6246</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5156">CVE-2023-5156</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4911">CVE-2023-4911</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0687">CVE-2023-0687</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3715">CVE-2022-3715</a> </li></ul></td>
</tr>
<tr>
<td><strong>494902472, 493902764, 493747531, 493747186, 493066364, 492956556, 492812098, 492810982, 492737291, 492733739, 492067214, 491191150, 490628133, 490627481, 490279890, 490278396, 489905507, 489904404, 477290192</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61728">CVE-2025-61728</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61724">CVE-2025-61724</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58186">CVE-2025-58186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58185">CVE-2025-58185</a> </li></ul></td>
</tr>
<tr>
<td><strong>494874583, 493352686, 493350530, 493065065, 492958506, 492958221, 492810419, 492734198, 492360831, 491606491, 491602959, 490628958, 490628720, 490625335, 489487288, 477290192</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61724">CVE-2025-61724</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47912">CVE-2025-47912</a> </li></ul></td>
</tr>
<tr>
<td><strong>493904046, 493748763, 493353749, 492959837, 492959353, 492958532, 492734063, 492358967, 491163162, 489907974, 489494841, 477290192</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27139">CVE-2026-27139</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61728">CVE-2025-61728</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58181">CVE-2025-58181</a> </li></ul></td>
</tr>
<tr>
<td><strong>493940049, 493935866, 492812693, 492811208, 490847438, 490285784, 443494822, 430609333, 428036268, 428035602</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22795">CVE-2026-22795</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69419">CVE-2025-69419</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69418">CVE-2025-69418</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5709">CVE-2018-5709</a> </li></ul></td>
</tr>
<tr>
<td><strong>494873893, 492957899, 492811896, 492735230, 492734621, 492362013, 492358145, 492044636, 491192904, 491163716, 490628292, 490283689, 489908590, 489487798, 485998102, 482978613</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68156">CVE-2025-68156</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47913">CVE-2025-47913</a> </li></ul></td>
</tr>
<tr>
<td><strong>495206280, 492736206, 492358267, 491606961, 491603879, 490845184, 490842872, 490626346, 490625529, 490278258, 489155677</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>492959491, 492959470, 492959266, 492812323, 492736535, 492736355, 492736200, 492734720, 492549333, 492528258, 492528186, 492361814, 492360845, 492359742, 492359020, 492039084, 490625473, 489488025, 489120498</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>492959323, 492958717, 492813153, 492736850, 492736096, 492735265, 492360419, 492359937, 492359237, 492041473, 491604321, 491602140, 490847572, 490627493, 490282905, 489151338, 489127231</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li></ul></td>
</tr>
<tr>
<td><strong>492736867, 492735320, 492550947, 492549407, 492360316, 492359543, 492358244, 491608063, 491603446, 491169265, 490282128, 490278007, 490276323, 489127588, 489124394</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li></ul></td>
</tr>
<tr>
<td><strong>492956844, 492956300, 492812417, 492811007, 492810814, 492528300, 492361776, 492360457, 492360310, 492360053, 492358006, 492037890, 491606683, 489492294, 489152529</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li></ul></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>March 12, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#March_12_2026</id>
    <updated>2026-03-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#March_12_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.0</strong>
<h3>Announcement</h3>
<h3 id="hybrid_1160-hotfix2">hybrid 1.16.0-hotfix.2</h3>
<p>On March 12, 2026 we released Apigee hybrid 1.16.0-hotfix.2.</p>
<aside class="special"><strong>Important:</strong><span> If your installation is already on Apigee hybrid v1.16.0, use the following procedure to apply this hotfix. For new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a> and then apply the hotfix to the new installation with the following instructions.</span></aside>
<h4 id="apply_this_hotfix_with_the_following_steps">Apply this hotfix with the following steps:</h4>
<aside class="note"><strong>Note:</strong><span> This release reflects a change to both the component images and the Helm chart templates.</span></aside>
<p>Apply this hotfix with the following steps:</p>
<ol>
<li>In your hybrid Helm charts directory, download the Apigee hybrid 1.16.0-hotfix.2 Helm charts into your hybrid Helm charts directory with the following commands:
<pre class="devsite-terminal">
export <b>CHART_REPO</b>=oci://us-docker.pkg.dev/apigee-release/apigee-hybrid-helm-charts
<code class="devsite-terminal">export <b>CHART_VERSION=1.16.0-hotfix.2</b></code>
<code class="devsite-terminal">helm pull <b>$CHART_REPO</b>/apigee-operator --version <b>$CHART_VERSION</b> --untar</code>
<code class="devsite-terminal">helm pull <b>$CHART_REPO</b>/apigee-datastore --version <b>$CHART_VERSION</b> --untar</code>
<code class="devsite-terminal">helm pull <b>$CHART_REPO</b>/apigee-env --version <b>$CHART_VERSION</b> --untar</code>
<code class="devsite-terminal">helm pull <b>$CHART_REPO</b>/apigee-ingress-manager --version <b>$CHART_VERSION</b> --untar</code>
<code class="devsite-terminal">helm pull <b>$CHART_REPO</b>/apigee-org --version <b>$CHART_VERSION</b> --untar</code>
<code class="devsite-terminal">helm pull <b>$CHART_REPO</b>/apigee-redis --version <b>$CHART_VERSION</b> --untar</code>
<code class="devsite-terminal">helm pull <b>$CHART_REPO</b>/apigee-telemetry --version <b>$CHART_VERSION</b> --untar</code>
<code class="devsite-terminal">helm pull <b>$CHART_REPO</b>/apigee-virtualhost --version <b>$CHART_VERSION</b> --untar</code>
</pre>
</li>
<li>Install the hotfix release for Apigee operators, beginning with a dry run:
<pre class="devsite-click-to-copy">
helm upgrade operator apigee-operator/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  -f overrides.yaml \
  --dry-run=server
</pre>
</li>
<li>After the dry run is successful, install the hotfix release for Apigee operators:
<pre class="devsite-click-to-copy">
helm upgrade operator apigee-operator/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  -f overrides.yaml
</pre>
</li>
<li>Install the hotfix release for your organization, beginning with a dry run:
<pre class="devsite-click-to-copy">
helm upgrade $ORG_NAME apigee-org/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  -f overrides.yaml \
  --dry-run=server
</pre>
</li>
<li>After the dry run is successful, install the hotfix release for your organization:
<pre class="devsite-click-to-copy">
helm upgrade $ORG_NAME apigee-org/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  -f overrides.yaml
</pre>
</li>
<li>Verify the organization chart by checking the state:
<pre class="devsite-click-to-copy">
kubectl -n <var>APIGEE_NAMESPACE</var> get apigeeorg
</pre>
</li>
<li>Install the hotfix release for your environments. Repeat the following steps for each environment, beginning with a dry run:
<pre class="devsite-click-to-copy">
helm upgrade <var>ENV_RELEASE_NAME</var> apigee-env/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  --set env=$ENV_NAME \
  -f overrides.yaml \
  --dry-run=server
</pre>
</li>
<li>After the dry run is successful, install the hotfix release for your environment:
<pre class="devsite-click-to-copy">
helm upgrade <var>ENV_RELEASE_NAME</var> apigee-env/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  --set env=$ENV_NAME \
  -f overrides.yaml
</pre>
</li>
<li>Verify the environment chart by checking the state:
<pre class="devsite-click-to-copy">
kubectl -n <var>APIGEE_NAMESPACE</var> get apigeeenv
</pre>
</li>
</ol>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>490308770</strong></td>
<td><strong>Fixed malformed <code>http_proxy</code> and <code>https_proxy</code> strings in Helm templates that occurred when using authenticated outbound proxy configurations.</strong></td>
</tr>
<tr>
<td><strong>488417252</strong></td>
<td><strong>Fixed an issue where the Apigee Operator guardrails pod failed to run on EKS with Workload Identity Federation (WIF) by ensuring it runs as the federated principal rather than the default service account.</strong></td>
</tr>
<tr>
<td><strong>485526221</strong></td>
<td><strong>Removed the deprecated <code>apigee-stackdriver-logging-agent</code> image from the <code>apigee-pull-push.sh</code> tool, resolving image pull failures during automated deployments.</strong></td>
</tr>
<tr>
<td><strong>484405364</strong></td>
<td><strong>Helm chart images with the <code>1.16.0-hotfix.2</code> tag are available for download.</strong></td>
</tr>
<tr>
<td><strong>482209901</strong></td>
<td><strong>Added the <code>watch</code> permission to the <code>apigee-manager</code> role to allow the controller to monitor Deployment resources and resolve watch failures in the namespace.</strong></td>
</tr>
<tr>
<td><strong>482077193</strong></td>
<td><strong>Fixed an issue where proxy chaining failed with HTTP 404 <code>route_not_found</code> errors in multi-organization, single-namespace configurations.</strong></td>
</tr>
<tr>
<td><strong>481793880</strong></td>
<td><strong>Fixed a bug in the <code>apigeeorg</code> admission webhook controller that prevented upgrading organizations when monetization was enabled.</strong></td>
</tr>
<tr>
<td><strong>479872706</strong></td>
<td><strong>Resolved an issue that prevented loading API products, apps, and developers after migrating data to Apigee hybrid 1.16.0 in configurations using Workload Identity Federation (WIF) with an HTTP Forward Proxy.</strong></td>
</tr>
<tr>
<td><strong>479040521</strong></td>
<td><strong>Resolved a regression where the <code>apigee-operator-guardrails-sa</code> ServiceAccount was not correctly created on AKS and EKS platforms with Federated Workload Identity enabled.</strong></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>March 11, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#March_11_2026</id>
    <updated>2026-03-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#March_11_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.15.2</strong>
<h3>Announcement</h3>
<h3 id="hybrid_v1152">hybrid v1.15.2</h3>
<p>On March 11, 2026 we released an updated version of the Apigee hybrid software, v1.15.2.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.2</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release_2">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>469694040</strong></td>
<td><strong>Fixed an issue where custom Java security policies were intermittently not applied during runtime pod restarts or environment contract updates, which could lead to "Permission denied" errors in Java callouts.</strong></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>471502899, 471173561</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li></ul></td>
</tr>
<tr>
<td><strong>471502752, 471191392</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li></ul></td>
</tr>
<tr>
<td><strong>471502495, 471501875, 471126425</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li></ul></td>
</tr>
<tr>
<td><strong>471016560, 471015664, 471015120</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40897">CVE-2022-40897</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47273">CVE-2025-47273</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a> </li></ul></td>
</tr>
<tr>
<td><strong>451224723, 451224123</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4756">CVE-2010-4756</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3389">CVE-2011-3389</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4392">CVE-2013-4392</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3276">CVE-2015-3276</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14159">CVE-2017-14159</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17740">CVE-2017-17740</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20796">CVE-2018-20796</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5709">CVE-2018-5709</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6829">CVE-2018-6829</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010022">CVE-2019-1010022</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010023">CVE-2019-1010023</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010024">CVE-2019-1010024</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010025">CVE-2019-1010025</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9192">CVE-2019-9192</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15719">CVE-2020-15719</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27943">CVE-2022-27943</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2953">CVE-2023-2953</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31437">CVE-2023-31437</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31438">CVE-2023-31438</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31439">CVE-2023-31439</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45853">CVE-2023-45853</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2236">CVE-2024-2236</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2379">CVE-2024-2379</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26458">CVE-2024-26458</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26461">CVE-2024-26461</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0725">CVE-2025-0725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10148">CVE-2025-10148</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27587">CVE-2025-27587</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62813">CVE-2025-62813</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9086">CVE-2025-9086</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9230">CVE-2025-9230</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9232">CVE-2025-9232</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-connect-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68121">CVE-2025-68121</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68121">CVE-2025-68121</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68156">CVE-2025-68156</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29786">CVE-2025-29786</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector:</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29786">CVE-2025-29786</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prom-prometheus</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47913">CVE-2025-47913</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68121">CVE-2025-68121</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61594">CVE-2025-61594</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24294">CVE-2025-24294</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68121">CVE-2025-68121</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li></ul></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>February 06, 2026</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#February_06_2026</id>
    <updated>2026-02-06T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#February_06_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">1.16.0-hotfix.1</strong>
<h3>Announcement</h3>
<h3 id="hybrid_1160-hotfix1">hybrid 1.16.0-hotfix.1</h3>
<p>On February 6, 2026 we released Apigee hybrid 1.16.0-hotfix.1.</p>
<aside class="special"><strong>Important:</strong><span> If your installation is already on Apigee hybrid v1.16.0, use the following procedure to apply this hotfix. For new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a> and then apply the hotfix to the new installation with the following instructions.</span></aside>
<h4 id="apply_this_hotfix_with_the_following_steps_2">Apply this hotfix with the following steps:</h4>
<aside class="note"><strong>Note:</strong><span> This hotfix installs the <code>apigee-mart-server</code> container images. All other container images are unchanged from Hybrid v1.16.0.</span></aside>
<ol>
<li>In your overrides file, update the <code>image.url</code> and <code>image.tag</code> properties of <code>ao</code> and <code>mart</code> to version <code>1.16.0-hotfix.1</code>:
<pre class="devsite-click-to-copy">
ao:
  image:
    url: "gcr.io/apigee-release/hybrid/apigee-operators"
    tag: "1.16.0-hotfix.1"

mart:
  image:
    url: "gcr.io/apigee-release/hybrid/apigee-mart-server"
    tag: "1.16.0-hotfix.1"
</pre>
</li>
<li>Install the hotfix release for Apigee operators, beginning with a dry run:
<pre class="devsite-click-to-copy">
helm upgrade operator apigee-operator/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  -f overrides.yaml \
  --dry-run=server
</pre>
</li>
<li>If the dry run is successful, install the hotfix release for Apigee operators:
<pre class="devsite-click-to-copy">
helm upgrade operator apigee-operator/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  -f overrides.yaml
</pre>
</li>
<li>Install the hotfix release for your organization, beginning with a dry run:
<pre class="devsite-click-to-copy">
helm upgrade $ORG_NAME apigee-org/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  -f overrides.yaml \
  --dry-run=server
</pre>
</li>
<li>If the dry run is successful, install the hotfix release for your organization:
<pre class="devsite-click-to-copy">
helm upgrade $ORG_NAME apigee-org/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  -f overrides.yaml
</pre>
</li>
<li>Verify the organization chart by checking the state:
<pre class="devsite-click-to-copy">
kubectl -n <var>APIGEE_NAMESPACE</var> get apigeeorg
</pre>
</li>
<li>Install the hotfix release for your environment, beginning with a dry run:
<pre class="devsite-click-to-copy">
helm upgrade <var>ENV_RELEASE_NAME</var> apigee-env/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  --set env=$ENV_NAME \
  -f overrides.yaml \
  --dry-run=server
</pre>
</li>
<li>If the dry run is successful, install the hotfix release for your environment:
<pre class="devsite-click-to-copy">
helm upgrade <var>ENV_RELEASE_NAME</var> apigee-env/ \
  --install \
  --namespace <var>APIGEE_NAMESPACE</var> \
  --atomic \
  --set env=$ENV_NAME \
  -f overrides.yaml
</pre>
</li>
<li>Verify the environment chart by checking the state:
<pre class="devsite-click-to-copy">
kubectl -n <var>APIGEE_NAMESPACE</var> get apigeeenv
</pre>
</li>
</ol>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release_3">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>479872706</strong></td>
<td><strong>An issue that prevented loading API products, apps, and developers after migrating data to Apigee hybrid 1.16.0 in certain configurations has been resolved.</strong></td>
</tr>
<tr>
<td><strong>481793880</strong></td>
<td><strong>An issue that prevented upgrading an existing organization when monetization was enabled has been fixed.</strong></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>December 19, 2025</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#December_19_2025</id>
    <updated>2025-12-19T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#December_19_2025"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.16.0</strong>
<h3>Announcement</h3>
<h3 id="hybrid_v1160">hybrid v1.16.0</h3>
<p>On December 19, 2025 we released an updated version of the Apigee hybrid software, 1.16.0.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a minor release: The container images used in minor releases are integrated with the Apigee hybrid Helm charts. Upgrading to a minor via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Seccomp Profiles</strong></p>
<p>Apigee Hybrid now offers the capability to apply Seccomp Profiles to your runtime components, significantly enhancing the security posture of your deployment.</p>
<p>This feature allows Apigee administrators and security teams to restrict the system calls (syscalls) a containerized process can make to the host's kernel. By limiting a container to only the necessary syscalls, you can:</p>
<ul>
<li>Enhance Security: Mitigate the risk of container breakouts and privilege escalation.</li>
<li>Enforce Least Privilege: Ensure components only have access to the exact system calls required for their operation.</li>
<li>Meet Compliance: Provide a critical control for meeting stringent security compliance requirements.</li>
</ul>
<p>Seccomp profiles are not enabled by default. To enable the feature, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/configure-seccomp-profiles">Configure Seccomp profiles for pod security</a>.</p>
<h3>Feature</h3>
<p><strong><code>apigee-guardrails</code> service account</strong></p>
<p>In v1.16.0, Apigee Hybrid introduces an <code>apigee-guardrails</code> Google IAM service account. This is used by the <code>apigee-operator</code> chart during initial installation to check that all needed APIs are enabled in your project.</p>
<aside class="note"><strong>Note:</strong><span> The <code>apigee-guardrails</code> service account is required for both upgraded and new installations. See <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade#set-up-the-apigee-guardrails-service-account">Upgrading to Apigee hybrid to version 1.16: Set up the <code>apigee-guardrails</code> service account</a> for upgrade instructions.</span></aside>
<p>See:</p>
<ul>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/guardrails">Diagnosing issues with guardrails</a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/sa-about#apigee-guardrails">About service accounts: <code>apigee-guardrails</code></a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/create-service-account"><code>create-service-account</code></a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade#changes-from-previous-version">Upgrading to Apigee hybrid to version 1.16</a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/install-service-accounts">Installation Part 2: Step 4: Create service accounts</a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/install-sa-authentication">Installation Part 2: Step 5: Set up service account authentication</a></li>
</ul>
<h3>Change</h3>
<p><strong>UDCA component removed</strong></p>
<p>In Apigee hybrid v1.16, the Unified Data Collection Agent (UDCA) component has been removed. The responsibilities of sending analytics, trace, and deployment status data to the Apigee control plane are now handled using a <a href="https://docs.cloud.google.com/pubsub/docs">Google Cloud Pub/Sub</a> based data pipeline. Using the Pub/Sub based data pipeline has been the default data collection mechanism since <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1140">Apigee hybrid v1.14.0</a>.</p>
<h3>Change</h3>
<p><strong>Support for cert-manager release 1.18 and 1.19</strong></p>
<p>Apigee hybrid v1.16 supports cert-manager release 1.18 and 1.19.</p>
<aside class="note"><strong>Note:</strong><span> cert-manager release 1.18 introduces a change to the default certificate <code>Spec.PrivateKey.RotationPolicy</code> value that can impact traffic on upgraded Apigee hybrid installations. This does not affect new installations of Apigee Hybrid. See <a href="https://docs.cloud.google.com/apigee/docs/release/known-issues#465834046">Known issue 465834046</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>448647917</strong></td>
<td><strong>Fixed a issue where non-SSL connections through a forward proxy could be improperly shared.</strong> (also fixed in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_31_2025">Apigee 1-16-0-apigee-4</a>)</td>
</tr>
<tr>
<td><strong>442501403</strong></td>
<td><strong>Fixed an issue that caused incorrect target latency metrics in Apigee Analytics when a TargetEndpoint is configured with a &lt;LoadBalancer&gt;.</strong> (also fixed in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_16_2025">Apigee 1-16-0-apigee-3</a>)</td>
</tr>
<tr>
<td><strong>438192028</strong></td>
<td><strong>Updated the geolocation database to mitigate stale IP-to-location mappings.</strong> (also fixed in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_16_2025">Apigee 1-16-0-apigee-3</a>)</td>
</tr>
<tr>
<td><strong>437999897</strong></td>
<td><strong>Reduced the log level for failed geo IP lookups to address excessive log messages for private IP addresses.</strong> (also fixed in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_16_2025">Apigee 1-16-0-apigee-3</a>)</td>
</tr>
<tr>
<td><strong>436323210</strong></td>
<td><strong>Fixed ingress cert keys to allow both <code>tls.key</code>/<code>key</code> and <code>tls.crt</code>/<code>cert</code>.</strong></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Updates to security, infrastructure, and libraries.</strong> (also fixed in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_31_2025">Apigee 1-16-0-apigee-4</a>)</td>
</tr>
</tbody>
</table>
<h3>Fixed</h3>
<h4 id="fixed_since_last_minor_release">Fixed since last minor release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>451841788</strong></td>
<td><strong>Apigee hybrid required the <code>mintTaskScheduler.serviceAccountPath</code> property even when Monetization was not enabled.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
<tr>
<td><strong>451375397</strong></td>
<td><strong>The <code>apigee-pull-push.sh</code> script could return a No such image error message.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
<tr>
<td><strong>445912919</strong></td>
<td><strong>Unused files and folders have been removed from the Apigee hybrid Helm charts to prevent potential security exposure and streamline the product installation and upgrade process.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>)</td>
</tr>
<tr>
<td><strong>442501403</strong></td>
<td><strong>Fixed an issue that caused incorrect target latency metrics in Apigee Analytics when a <code>TargetEndpoint</code> is configured with a <code>&lt;LoadBalancer&gt;</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>)</td>
</tr>
<tr>
<td><strong>437999897</strong></td>
<td><strong>Reduced the log level for failed geo IP lookups to address excessive log messages for private IP addresses.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>)</td>
</tr>
<tr>
<td><strong>431930277</strong>, <strong>395272878</strong></td>
<td><strong>When the configuration property <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#envs-managementcallsskipproxy"><code>envs.managementCallsSkipProxy</code></a> is set to <code>true</code> via helm for environment-level forward proxy, trace and analytics (which use <code>googleapis.com</code>) will skip forward proxy.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>)</td>
</tr>
<tr>
<td><strong>423597917</strong></td>
<td><strong>Post of an <a href="https://docs.cloud.google.com/apigee/docs/reference/apis/apigee/rest/v1/organizations.appgroups.apps.keys/updateAppGroupAppKey"><code>AppGroupAppKey</code></a> scopes should result in insert operation instead of update.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
<tr>
<td><strong>420675540</strong></td>
<td><strong>Fixed Cassandra based replication for runtime contracts in synchronizer.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>, <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1134">v1.13.4</a>)</td>
</tr>
<tr>
<td><strong>419578402</strong></td>
<td><strong>Mint-Mart forward proxy compatible.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
<tr>
<td><strong>416634326</strong></td>
<td><strong>Presence of istio.io Custom Resource Definitions (CRDs) in an Apigee hybrid cluster could cause failure in apigee-ingressgateway-manager pods.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>, <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1134">v1.13.4</a>)</td>
</tr>
<tr>
<td><strong>414499328</strong></td>
<td><strong><code>ApigeeTelemetry</code> could become stuck in <code>creating</code> state</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1134">v1.13.4</a>)</td>
</tr>
<tr>
<td><strong>412740465</strong></td>
<td><strong>Fixed issue where zipkin headers were not generated by Apigee Ingress Gateway.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
<tr>
<td><strong>409048431</strong></td>
<td><strong>Fixes a vulnerability which could allow a SAML signature verification to be bypassed.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
<tr>
<td><strong>401746333</strong></td>
<td><strong>Fixed a <code>java.lang.ClassCircularityError</code> that could occur in Java Callouts due to an issue with the class loading mechanism.</strong>(Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
<tr>
<td><strong>395272878</strong></td>
<td><strong>Separate Forward proxy support for <code>googleapis.com</code> and <code>non-googleapis.com</code> runtime traffic.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
<tr>
<td><strong>393615439</strong></td>
<td><strong>OASValidation behavior for <code>allOf</code> with <code>additionalProperties: true</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_1142-hotfix1">1.14.2-hotfix.1</a>)</td>
</tr>
<tr>
<td><strong>382565315</strong></td>
<td><strong>A memory leak within the Security Policy has been addressed, improving system stability.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1134">v1.13.4</a>)</td>
</tr>
<tr>
<td><strong>378686709</strong></td>
<td><strong>The use of wildcards (*) in Apigee proxy basepaths would conflict with other explicit basepaths, resulting in a 404 error.</strong> To apply this fix, follow the procedure in <a href="https://docs.cloud.google.com/apigee/docs/release/known-issues#378686709">Known issue 378686709</a>. (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
<tr>
<td><strong>375360455</strong></td>
<td><strong>Updated apigee-runtime drain timeout to 300s to fix connection termination issue during pod termination.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1134">v1.13.4</a>)</td>
</tr>
<tr>
<td><strong>367815792</strong></td>
<td><strong>Two new Flow Variables: <code>app_group_app</code> and <code>app_group_name</code> have been added to VerifyApiKey and Access Token policy.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>)</td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<h4 id="fixed_in_this_release_2">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>452621774, 452381632, 441266643, 448498138</strong></td>
<td><strong>Security fix for Apigee infrastructure.</strong> (also fixed in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_31_2025">Apigee 1-16-0-apigee-4</a>) <br/>This addresses the following vulnerabilities:<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53864">CVE-2025-53864</a><p>Updated Nimbus JWT library from 9.37.2 to 9.37.4, which introduced changes in behavior including changes to error string verbiage.</p></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8916">CVE-2025-8916</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5115">CVE-2025-5115</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40094">CVE-2024-40094</a></li></ul></td>
</tr>
<tr>
<td><strong>440419558, 433759657</strong></td>
<td><strong>Security fix for Apigee infrastructure.</strong> (also fixed in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_16_2025">Apigee 1-16-0-apigee-3</a>) <p>This addresses the following vulnerabilities:<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22868">CVE-2025-22868</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a></li><aside class="note"><b>Note</b>: This fix updates a Java library that is included in Apigee.  Reliance on Java libraries that are included with Apigee is not supported. Those libraries are for Apigee product functionality only, and there's no guarantee that a library will be available from release to release. For more information, see <a href="https://docs.cloud.google.com/apigee/docs/api-platform/reference/policies/java-callout-policy#Restrictions">Restrictions</a>.</aside></ul></p></td>
</tr>
<tr>
<td><strong>443902061</strong></td>
<td><strong>Security fix for Apigee infrastructure</strong> (also fixed in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_16_2025">Apigee 1-16-0-apigee-3</a>) <p>This addresses the following vulnerability:<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13292">CVE-2025-13292</a><p>Fixed an issue with improper access control that resulted in cross-tenant analytics modification and access to log data.</p></li></ul></p></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-connect-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9230">CVE-2025-9230</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47913">CVE-2025-47913</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53066">CVE-2025-53066</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50106">CVE-2025-50106</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50059">CVE-2025-50059</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48913">CVE-2025-48913</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30749">CVE-2025-30749</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13009">CVE-2024-13009</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29786">CVE-2025-29786</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prom-prometheus</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48174">CVE-2022-48174</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50106">CVE-2025-50106</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50059">CVE-2025-50059</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48913">CVE-2025-48913</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30749">CVE-2025-30749</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24294">CVE-2025-24294</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50106">CVE-2025-50106</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50059">CVE-2025-50059</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48913">CVE-2025-48913</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30749">CVE-2025-30749</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47913">CVE-2025-47913</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li></ul></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<h4 id="fixed_since_last_minor_release_2">Fixed since last minor release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>448498138</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40094">CVE-2024-40094</a></li> </ul></td>
</tr>
<tr>
<td><strong>447367372</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a></li> </ul></td>
</tr>
<tr>
<td><strong>433952146</strong></td>
<td><strong>Security fix.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6763">CVE-2024-6763</a> </li></ul></td>
</tr>
<tr>
<td><strong>433951774</strong></td>
<td><strong>Security fix.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7254">CVE-2024-7254</a> </li></ul></td>
</tr>
<tr>
<td><strong>433950558</strong></td>
<td><strong>Security fix.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47554">CVE-2024-47554</a> </li></ul></td>
</tr>
<tr>
<td><strong>433950370</strong></td>
<td><strong>Security fix.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25193">CVE-2025-25193</a> </li></ul></td>
</tr>
<tr>
<td><strong>418557195</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>) <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24528">CVE-2025-24528</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4207">CVE-2025-4207</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1390">CVE-2025-1390</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26462">CVE-2024-26462</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13176">CVE-2024-13176</a></li> </ul></td>
</tr>
<tr>
<td><strong>396944778</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1134">v1.13.4</a>) <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25193">CVE-2025-25193</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24970">CVE-2025-24970</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23184">CVE-2025-23184</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47554">CVE-2024-47554</a></li> </ul></td>
</tr>
<tr>
<td><strong>392934392</strong></td>
<td><strong>Security fixes for <code>apigee-logger</code>.</strong></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Incorporated an updated base image for <code>stackdriver-logging-agent</code>, improving the overall security of the service.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_1142-hotfix1">1.14.2-hotfix.1</a>) <br/>This addresses the following vulnerabilities (among others and not limited to): <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32221">CVE-2022-32221</a> </li> <li><a href="https://osv.dev/vulnerability/GHSA-jvgm-pfqv-887x">GHSA-jvgm-pfqv-887x</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-envoy</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0395">CVE-2025-0395</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a> &amp; <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>) <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32990">CVE-2025-32990</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32988">CVE-2025-32988</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23015">CVE-2025-23015</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24970">CVE-2025-24970</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1151">v1.15.1</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23015">CVE-2025-23015</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1134">v1.13.4</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20952">CVE-2024-20952</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">v1.14.3</a>) <br/>This addresses the following vulnerabilities: <ul> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48795">CVE-2025-48795</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48734">CVE-2025-48734</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24970">CVE-2025-24970</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47554">CVE-2024-47554</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47535">CVE-2024-47535</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13009">CVE-2024-13009</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8184">CVE-2024-8184</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7254">CVE-2024-7254</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6763">CVE-2024-6763</a> </li> </ul></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>October 12, 2025</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#October_12_2025</id>
    <updated>2025-10-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#October_12_2025"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.15.1</strong>
<h3>Announcement</h3>
<h3 id="hybrid_v1151">hybrid v1.15.1</h3>
<p>On October 10, 2025 we released an updated version of the Apigee hybrid software, 1.15.1.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version 1.15</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Recurring, top-up, and setup fees for Apigee hybrid monetization</strong></p>
<p>Apigee hybrid now supports recurring, top-up, and setup fees for monetization. For information see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/monetization-for-hybrid">Enabling monetization for Apigee hybrid</a>.</p>
<h3>Feature</h3>
<p><strong>Apigee policies for LLM/GenAI workloads</strong></p>
<p>Apigee hybrid now supports the following Apigee policies with support for LLM/GenAI workloads.</p>
<ul>
<li><a href="https://docs.cloud.google.com/apigee/docs/api-platform/reference/policies/semantic-cache-lookup-policy">SemanticCacheLookup policy</a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/api-platform/reference/policies/semantic-cache-populate-policy">SemanticCachePopulate policy</a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/api-platform/reference/policies/sanitize-user-prompt-policy">SanitizeUserPrompt</a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/api-platform/reference/policies/sanitize-user-prompt-policy">SanitizeModelResponse</a></li>
</ul>
<p>The Apigee semantic caching policies enable intelligent response reuse based on semantic similarity. Using these policies in your Apigee API proxies can minimize redundant backend API calls, reduce latency, and lower operational costs. With this release, the semantic caching policies support URL templating, enabling the use of variables for AI model endpoint values.</p>
<p>The Model Armor policies protect your AI applications by sanitizing user prompts to and responses from large language models (LLMs). Using these policies in your Apigee API proxies can mitigate the risks associated with LLM usage by leveraging Model Armor to detect prompt injection, prevent jailbreak attacks, apply responsible AI filters, filter malicious URLs, and protect sensitive data.</p>
<aside class="note"><b>Note:</b> In Apigee hybrid, this feature has the following limitations:
  <ul>
<li>Support for these policies is limited to installations on Google Cloud Platform.</li>
<li>Apigee hybrid does not support forward proxy with these policies.</li>
</ul>
</aside>
<p>For more information on using these policies in your Apigee API proxies, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/apigee/docs/api-platform/tutorials/using-semantic-caching-policies">Get started with semantic caching policies</a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/api-platform/tutorials/using-model-armor-policies">Get started with Apigee Model Armor policies</a></li>
</ul>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>451841788</strong></td>
<td><strong>Apigee hybrid required the <code>mintTaskScheduler.serviceAccountPath</code> property even when Monetization was not enabled.</strong></td>
</tr>
<tr>
<td><strong>451375397</strong></td>
<td><strong>The <code>apigee-pull-push.sh</code> script could return a "No such image error" message.</strong></td>
</tr>
<tr>
<td><strong>445912919</strong></td>
<td><strong>Unused files and folders have been removed from the Apigee hybrid Helm charts to prevent potential security exposure and streamline the product installation and upgrade process.</strong></td>
</tr>
<tr>
<td><strong>442501403</strong></td>
<td><strong>Fixed an issue that caused incorrect target latency metrics in Apigee Analytics when a <code>TargetEndpoint</code> is configured with a <code>&lt;LoadBalancer&gt;</code>.</strong></td>
</tr>
<tr>
<td><strong>437999897</strong></td>
<td><strong>Reduced the log level for failed geo IP lookups to address excessive log messages for private IP addresses.</strong></td>
</tr>
<tr>
<td><strong>431930277</strong>, <strong>395272878</strong></td>
<td><strong>When the configuration property <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#envs-managementcallsskipproxy"><code>envs.managementCallsSkipProxy</code></a> is set to <code>true</code> via helm for environment-level forward proxy, trace and analytics (which use <code>googleapis.com</code>) will skip forward proxy.</strong></td>
</tr>
<tr>
<td><strong>423597917</strong></td>
<td><strong>Post of an <a href="https://docs.cloud.google.com/apigee/docs/reference/apis/apigee/rest/v1/organizations.appgroups.apps.keys/updateAppGroupAppKey"><code>AppGroupAppKey</code></a> scopes should result in insert operation instead of update.</strong></td>
</tr>
<tr>
<td><strong>420675540</strong></td>
<td><strong>Fixed Cassandra based replication for runtime contracts in synchronizer.</strong></td>
</tr>
<tr>
<td><strong>419578402</strong></td>
<td><strong>Mint-Mart forward proxy compatible.</strong></td>
</tr>
<tr>
<td><strong>416634326</strong></td>
<td><strong>Presence of istio.io Custom Resource Definitions (CRDs) in an Apigee hybrid cluster could cause failure in apigee-ingressgateway-manager pods.</strong></td>
</tr>
<tr>
<td><strong>412740465</strong></td>
<td><strong>Fixed issue where zipkin headers were not generated by Apigee Ingress Gateway.</strong></td>
</tr>
<tr>
<td><strong>409048431</strong></td>
<td><strong>Fixes a vulnerability which could allow a SAML signature verification to be bypassed.</strong></td>
</tr>
<tr>
<td><strong>378686709</strong></td>
<td><strong>The use of wildcards (*) in Apigee proxy basepaths would conflict with other explicit basepaths, resulting in a 404 error.</strong> To apply this fix, follow the procedure in <a href="https://docs.cloud.google.com/apigee/docs/release/known-issues#378686709">Known issue 378686709</a>.</td>
</tr>
<tr>
<td><strong>367815792</strong></td>
<td><strong>Two new Flow Variables: <code>app_group_app</code> and <code>app_group_name</code> have been added to VerifyApiKey and Access Token policy.</strong></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>448498138</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40094">CVE-2024-40094</a></li> </ul></td>
</tr>
<tr>
<td><strong>447367372</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a></li> </ul></td>
</tr>
<tr>
<td><strong>418557195</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24528">CVE-2025-24528</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4207">CVE-2025-4207</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1390">CVE-2025-1390</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26462">CVE-2024-26462</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13176">CVE-2024-13176</a></li> </ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32990">CVE-2025-32990</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32988">CVE-2025-32988</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23015">CVE-2025-23015</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerabilities: <ul> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056">CVE-2025-58056</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48795">CVE-2025-48795</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48734">CVE-2025-48734</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24970">CVE-2025-24970</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47554">CVE-2024-47554</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47535">CVE-2024-47535</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13009">CVE-2024-13009</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8184">CVE-2024-8184</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7254">CVE-2024-7254</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6763">CVE-2024-6763</a> </li> </ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58767">CVE-2025-58767</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24294">CVE-2025-24294</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33953">CVE-2023-33953</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32511">CVE-2022-32511</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29181">CVE-2022-29181</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24839">CVE-2022-24839</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24836">CVE-2022-24836</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0759">CVE-2022-0759</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41817">CVE-2021-41817</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31799">CVE-2021-31799</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30560">CVE-2021-30560</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28965">CVE-2021-28965</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23214">CVE-2021-23214</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25695">CVE-2020-25695</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25694">CVE-2020-25694</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25613">CVE-2020-25613</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3881">CVE-2019-3881</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25032">CVE-2018-25032</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1115">CVE-2018-1115</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10915">CVE-2018-10915</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1058">CVE-2018-1058</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1053">CVE-2018-1053</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7546">CVE-2017-7546</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7484">CVE-2017-7484</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15098">CVE-2017-15098</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14798">CVE-2017-14798</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7954">CVE-2016-7954</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7048">CVE-2016-7048</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5424">CVE-2016-5424</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5423">CVE-2016-5423</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0766">CVE-2016-0766</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3167">CVE-2015-3167</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3166">CVE-2015-3166</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0244">CVE-2015-0244</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0243">CVE-2015-0243</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0241">CVE-2015-0241</a> </li></ul></td>
</tr>
</tbody>
</table>
<h3>Change</h3>
<p><strong>Documentation change</strong></p>
<p>The following documents have been changed or introduced to align the Apigee hybrid installation guides with the supported methods for service account authentication:</p>
<ul>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/sa-authentication-methods">Service account authentication methods in Apigee hybrid</a> - A new overview topic for service account authentication.</li>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/storing-sa-keys-in-k8s-secrets">Storing service account keys in Kubernetes secrets</a> - A new topic.</li>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/install-service-accounts">Step 4: Create service accounts</a> - Rewritten to accommodate all supported methods of service account authentication.</li>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/install-sa-authentication">Step 5: Set up service account authentication</a> - A new topic on configuring authentication after creating service accounts.</li>
<li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/install-create-overrides">Step 7: Create the overrides</a> and <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/install-helm-charts">Step 11: Install Apigee hybrid Using Helm</a> - Topics revised to provide templates, examples, and procedures for each supported type of service account authentication.</li>
<li><strong>Step 11(Optional): Configure Workload Identity</strong> - Topic removed. The procedures are included in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/install-helm-charts.html#wif-for-gke">Step 11: Install Apigee hybrid Using Helm: WIF for GKE</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>October 07, 2025</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#October_07_2025</id>
    <updated>2025-10-07T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#October_07_2025"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.14.3</strong>
<h3>Announcement</h3>
<h3 id="hybrid_v1143">hybrid v1.14.3</h3>
<p>On October 7, 2025 we released an enhancement to Apigee hybrid version 1.14.3, recurring, top-up, and setup fees for Apigee hybrid monetization.</p>
<aside class="note"><strong>Note:</strong><span> This is an enhancement to an existing release.</span></aside>
<ul>
<li>For complete information on the contents of the v1.14.3 release, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1143">Apigee hybrid v1.14.3 release notes</a>.</li>
</ul>
<h3>Feature</h3>
<p><strong>Recurring, top-up, and setup fees for Apigee hybrid monetization</strong></p>
<p>Apigee hybrid now supports recurring, top-up, and setup fees for monetization. For information see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/monetization-for-hybrid">Enabling monetization for Apigee hybrid</a>.</p>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>419578402</strong></td>
<td><strong>Mint-Mart forward proxy compatible.</strong></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>September 29, 2025</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#September_29_2025</id>
    <updated>2025-09-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#September_29_2025"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.14.3</strong>
<h3>Announcement</h3>
<h3 id="hybrid_v1143">hybrid v1.14.3</h3>
<p>On September 29, 2025 we released an updated version of the Apigee hybrid software, 1.14.3.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version 1.14</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>451841788</strong></td>
<td><strong>Apigee hybrid required the <code>mintTaskScheduler.serviceAccountPath</code> property even when Monetization was not enabled.</strong></td>
</tr>
<tr>
<td><strong>451375397</strong></td>
<td><strong>The <code>apigee-pull-push.sh</code> script could return a "No such image" error message.</strong></td>
</tr>
<tr>
<td><strong>423597917</strong></td>
<td><strong>Post of an <a href="https://docs.cloud.google.com/apigee/docs/reference/apis/apigee/rest/v1/organizations.appgroups.apps.keys/updateAppGroupAppKey"><code>AppGroupAppKey</code></a> scopes should result in insert operation instead of update.</strong></td>
</tr>
<tr>
<td><strong>420675540</strong></td>
<td><strong>Fixed Cassandra based replication for runtime contracts in synchronizer.</strong></td>
</tr>
<tr>
<td><strong>416634326</strong></td>
<td><strong>Presence of istio.io Custom Resource Definitions (CRDs) in an Apigee hybrid cluster could cause failure in apigee-ingressgateway-manager pods.</strong></td>
</tr>
<tr>
<td><strong>414499328</strong></td>
<td><strong><code>ApigeeTelemetry</code> could become stuck in <code>creating</code> state</strong></td>
</tr>
<tr>
<td><strong>412740465</strong></td>
<td><strong>Fixed issue where zipkin headers were not generated by Apigee Ingress Gateway.</strong></td>
</tr>
<tr>
<td><strong>409048431</strong></td>
<td><strong>Fixes a vulnerability which could allow a SAML signature verification to be bypassed.</strong></td>
</tr>
<tr>
<td><strong>395272878</strong></td>
<td><strong>Separate Forward proxy support for <code>googleapis.com</code> and <code>non-googleapis.com</code> runtime traffic.</strong></td>
</tr>
<tr>
<td><strong>378686709</strong></td>
<td><strong>The use of wildcards (*) in Apigee proxy basepaths would conflict with other explicit basepaths, resulting in a 404 error.</strong> To apply this fix, follow the procedure in <a href="https://docs.cloud.google.com/apigee/docs/release/known-issues#378686709">Known issue 378686709</a>.</td>
</tr>
<tr>
<td><strong>367815792</strong></td>
<td><strong>Two new Flow Variables: <code>app_group_app</code> and <code>app_group_name</code> have been added to VerifyApiKey and Access Token policy.</strong></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>433952146</strong></td>
<td><strong>Security fix.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6763">CVE-2024-6763</a> </li></ul></td>
</tr>
<tr>
<td><strong>433951774</strong></td>
<td><strong>Security fix.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7254">CVE-2024-7254</a> </li></ul></td>
</tr>
<tr>
<td><strong>433950558</strong></td>
<td><strong>Security fix.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47554">CVE-2024-47554</a> </li></ul></td>
</tr>
<tr>
<td><strong>433950370</strong></td>
<td><strong>Security fix.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25193">CVE-2025-25193</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-envoy</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0395">CVE-2025-0395</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32990">CVE-2025-32990</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32988">CVE-2025-32988</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23015">CVE-2025-23015</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24970">CVE-2025-24970</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerabilities: <ul> <li><a href="https://nvd.nist.gov/vuln/detail/2025-48924">CVE-2025-48924</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/2025-48795">CVE-2025-48795</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/2025-48734">CVE-2025-48734</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/2025-24970">CVE-2025-24970</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/2024-47554">CVE-2024-47554</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/2024-47535">CVE-2024-47535</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/2024-13009">CVE-2024-13009</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/2024-8184">CVE-2024-8184</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/2024-7254">CVE-2024-7254</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/2024-6763">CVE-2024-6763</a> </li> </ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43857">CVE-2025-43857</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41946">CVE-2024-41946</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41123">CVE-2024-41123</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25062">CVE-2024-25062</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42915">CVE-2023-42915</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33953">CVE-2023-33953</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34169">CVE-2022-34169</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32511">CVE-2022-32511</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32207">CVE-2022-32207</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29181">CVE-2022-29181</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28739">CVE-2022-28739</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27782">CVE-2022-27782</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24839">CVE-2022-24839</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24836">CVE-2022-24836</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23308">CVE-2022-23308</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0759">CVE-2022-0759</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41819">CVE-2021-41819</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41817">CVE-2021-41817</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4044">CVE-2021-4044</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3518">CVE-2021-3518</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3517">CVE-2021-3517</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32740">CVE-2021-32740</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32066">CVE-2021-32066</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31799">CVE-2021-31799</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30560">CVE-2021-30560</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28966">CVE-2021-28966</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28965">CVE-2021-28965</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23214">CVE-2021-23214</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22926">CVE-2021-22926</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7595">CVE-2020-7595</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25695">CVE-2020-25695</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25694">CVE-2020-25694</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25613">CVE-2020-25613</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9193">CVE-2019-9193</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3881">CVE-2019-3881</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20388">CVE-2019-20388</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10211">CVE-2019-10211</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10210">CVE-2019-10210</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10128">CVE-2019-10128</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10127">CVE-2019-10127</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25032">CVE-2018-25032</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1115">CVE-2018-1115</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10915">CVE-2018-10915</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1058">CVE-2018-1058</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1053">CVE-2018-1053</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7546">CVE-2017-7546</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7486">CVE-2017-7486</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7484">CVE-2017-7484</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17405">CVE-2017-17405</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15098">CVE-2017-15098</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14798">CVE-2017-14798</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7954">CVE-2016-7954</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7048">CVE-2016-7048</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5424">CVE-2016-5424</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5423">CVE-2016-5423</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0766">CVE-2016-0766</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3167">CVE-2015-3167</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3166">CVE-2015-3166</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0244">CVE-2015-0244</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0243">CVE-2015-0243</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0242">CVE-2015-0242</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0241">CVE-2015-0241</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>September 24, 2025</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#September_24_2025</id>
    <updated>2025-09-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#September_24_2025"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.15.0</strong>
<h3>Announcement</h3>
<h3 id="apigee_operator_for_kubernetes_for_apigee_hybrid_preview">Apigee Operator for Kubernetes for Apigee Hybrid (Preview)</h3>
<p>On September 24, 2025 we released the Apigee Operator for Kubernetes for Apigee Hybrid 1.15.0 and newer.</p>
<p>The Apigee Operator for Kubernetes allows you to perform API management tasks, such as defining API products and operations, using Kubernetes tools. This preview release allows you to integrate this capability with your Apigee hybrid (v1.15.0 or newer) installation.</p>
<p>For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/apigee/docs/api-platform/apigee-kubernetes/apigee-apim-operator-overview">Apigee Operator for Kubernetes overview</a></li>
<li><a href="https://docs.cloud.google.com/apigee/docs/api-platform/apigee-kubernetes/apigee-apim-operator-install-hybrid">Install the Apigee Operator for Kubernetes for Apigee hybrid</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>July 09, 2025</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#July_09_2025</id>
    <updated>2025-07-09T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#July_09_2025"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.13.4</strong>
<h3>Announcement</h3>
<h3 id="hybrid_v1134">hybrid v1.13.4</h3>
<p>On July 9, 2025 we released an updated version of the Apigee hybrid software, 1.13.4.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.13/upgrade">Upgrading Apigee hybrid to version 1.13</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.13/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> if you are upgrading to Apigee hybrid version 1.13.4 from version 1.13.2 or earlier, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.13/upgrade#recommended-actions-upgrade-1133">APPENDIX: Validate policies after upgrade to 1.13.3 or later</a> for steps to address stricter class instantiation checks introduced in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1133">version 1.13.3</a>.</span></aside><aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>420675540</strong></td>
<td><strong>Fixed Cassandra based replication for runtime contracts in synchronizer.</strong></td>
</tr>
<tr>
<td><strong>401746333</strong></td>
<td><strong>Fixed a <code>java.lang.ClassCircularityError</code> that could occur in Java Callouts due to an issue with the class loading mechanism.</strong></td>
</tr>
<tr>
<td><strong>382565315</strong></td>
<td><strong>A memory leak within the Security Policy has been addressed, improving system stability.</strong></td>
</tr>
<tr>
<td><strong>375360455</strong></td>
<td><strong>Updated apigee-runtime drain timeout to 300s to fix connection termination issue during pod termination.</strong></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>396944778</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25193">CVE-2025-25193</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24970">CVE-2025-24970</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23184">CVE-2025-23184</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47554">CVE-2024-47554</a></li> </ul></td>
</tr>
<tr>
<td><strong>392934392</strong></td>
<td><strong>Security fixes for <code>apigee-logger</code>.</strong></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20952">CVE-2024-20952</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mint-task-scheduler</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20952">CVE-2024-20952</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24834">CVE-2022-24834</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24735">CVE-2022-24735</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20952">CVE-2024-20952</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20952">CVE-2024-20952</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>vault</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0377">CVE-2025-0377</a> </li></ul></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>June 04, 2025</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#June_04_2025</id>
    <updated>2025-06-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#June_04_2025"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.15.0</strong>
<h3>Announcement</h3>
<h3 id="hybrid_v1150">hybrid v1.15.0</h3>
<p>On June 4, 2025 we released an updated version of the Apigee hybrid software, 1.15.0.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version 1.15</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a minor release: The container images used in minor releases are integrated with the Apigee hybrid Helm charts. Upgrading to a minor via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Large message payload support in Apigee hybrid</strong></p>
<p>Apigee now supports message payloads up to 30MB. You configure support for large message payloads in Apigee hybrid for individual environments or for your whole installation. See <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/configure-large-payload-support">Configure large message payload support in Apigee hybrid</a>.</p>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>414499328</strong></td>
<td><strong><code>ApigeeTelemetry</code> could become stuck in <code>creating</code> state</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1150">v1.15.0</a>)</td>
</tr>
<tr>
<td><strong>412324617</strong></td>
<td><strong>Fixed issue where Runtime container could spin at 100% cpu limit.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)</td>
</tr>
<tr>
<td><strong>399447688</strong></td>
<td><strong>API proxy deployment could become stuck in <code>PROGRESSING</code> state.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)</td>
</tr>
<tr>
<td><strong>396886110</strong></td>
<td><strong>Fixed a bug where the HPA max replicas could be lower than min.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)</td>
</tr>
<tr>
<td><strong>413708061</strong>, <strong>396571537</strong></td>
<td><strong>Rotating Cassandra credentials in Kubernetes secrets fixed for Multi-region deployments.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)</td>
</tr>
<tr>
<td><strong>392547038</strong></td>
<td><strong>Add Helm chart template checks for non-existent environments and virtualhosts.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)</td>
</tr>
<tr>
<td><strong>391861216</strong></td>
<td><strong>Restore for Google Cloud Platform and HYBRID Cloud Providers no longer affects system keyspaces. This fixes <a href="https://docs.cloud.google.com/apigee/docs/release/known-issues#391861216">Known Issue 391861216</a>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)</td>
</tr>
<tr>
<td><strong>390258745</strong>, <strong>388608440</strong></td>
<td><strong>Any left over Cassandra snapshots are automatically removed. This fixes <a href="https://docs.cloud.google.com/apigee/docs/release/known-issues#388608440">known issue 388608440</a>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)</td>
</tr>
<tr>
<td><strong>384937220</strong></td>
<td><strong>Fixed <code>ApigeeRoute</code> name collision on internal chaining gateway for Enhanced Proxy Limits.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)</td>
</tr>
<tr>
<td><strong>383441226</strong></td>
<td><strong>Added the following <code>metrics</code> configuration properties:</strong> <ul><li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#metrics-adapter-resources-limits-cpu">metrics.adapter.resources.limits.cpu</a></li> <li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#metrics-adapter-resources-limits-memory">metrics.adapter.resources.limits.memory</a></li> <li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#metrics-adapter-resources-requests-cpu">metrics.adapter.resources.requests.cpu</a></li> <li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#metrics-adapter-resources-requests-memory">metrics.adapter.resources.requests.memory</a></li> <li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#metrics-prometheus-resources-limits-cpu">metrics.prometheus.resources.limits.cpu</a></li> <li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#metrics-prometheus-resources-limits-memory">metrics.prometheus.resources.limits.memory</a></li> <li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#metrics-prometheus-resources-requests-cpu">metrics.prometheus.resources.requests.cpu</a></li> <li><a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#metrics-prometheus-resources-requests-memory">metrics.prometheus.resources.requests.memory</a></li> </ul> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)</td>
</tr>
<tr>
<td><strong>368155212</strong></td>
<td><strong>Auto Cassandra secret rotation could fail when <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/enhanced-proxy-limits">Enhanced per-environment proxy limits</a> are enabled.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)</td>
</tr>
<tr>
<td><strong>367681534</strong></td>
<td><strong>Tagging <a href="http://gcr.io/apigee-release/hybrid/apigee-stackdriver-prometheus-sidecar:0.10.0"><code>apigee-stackdriver-prometheus-sidecar</code></a> to prevent removal from customer repos after 2 years due to infrequent updates.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_1140-hotfix1">1.14.0-hotfix.1</a>)</td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<p><strong>Fixed in this release</strong></p>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-connect-agent</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-envoy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4802">CVE-2025-4802</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0395">CVE-2025-0395</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4802">CVE-2025-4802</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23015">CVE-2025-23015</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3715">CVE-2022-3715</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prom-prometheus</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22869">CVE-2025-22869</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24791">CVE-2024-24791</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0725">CVE-2025-0725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3715">CVE-2022-3715</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43857">CVE-2025-43857</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32415">CVE-2025-32415</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32414">CVE-2025-32414</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27788">CVE-2025-27788</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27113">CVE-2025-27113</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49761">CVE-2024-49761</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41946">CVE-2024-41946</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41123">CVE-2024-41123</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25062">CVE-2024-25062</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42915">CVE-2023-42915</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33953">CVE-2023-33953</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34169">CVE-2022-34169</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32511">CVE-2022-32511</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32207">CVE-2022-32207</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29181">CVE-2022-29181</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28739">CVE-2022-28739</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27782">CVE-2022-27782</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24839">CVE-2022-24839</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24836">CVE-2022-24836</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23308">CVE-2022-23308</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0759">CVE-2022-0759</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41819">CVE-2021-41819</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41817">CVE-2021-41817</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4044">CVE-2021-4044</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3518">CVE-2021-3518</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3517">CVE-2021-3517</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32740">CVE-2021-32740</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32066">CVE-2021-32066</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31799">CVE-2021-31799</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30560">CVE-2021-30560</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28966">CVE-2021-28966</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28965">CVE-2021-28965</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23214">CVE-2021-23214</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22926">CVE-2021-22926</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7595">CVE-2020-7595</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25695">CVE-2020-25695</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25694">CVE-2020-25694</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25613">CVE-2020-25613</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9193">CVE-2019-9193</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3881">CVE-2019-3881</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20388">CVE-2019-20388</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10211">CVE-2019-10211</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10210">CVE-2019-10210</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10128">CVE-2019-10128</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10127">CVE-2019-10127</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25032">CVE-2018-25032</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1115">CVE-2018-1115</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10915">CVE-2018-10915</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1058">CVE-2018-1058</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1053">CVE-2018-1053</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7546">CVE-2017-7546</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7486">CVE-2017-7486</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7484">CVE-2017-7484</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17405">CVE-2017-17405</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15098">CVE-2017-15098</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14798">CVE-2017-14798</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7954">CVE-2016-7954</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7048">CVE-2016-7048</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5424">CVE-2016-5424</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5423">CVE-2016-5423</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0766">CVE-2016-0766</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3167">CVE-2015-3167</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3166">CVE-2015-3166</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0244">CVE-2015-0244</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0243">CVE-2015-0243</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0242">CVE-2015-0242</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0241">CVE-2015-0241</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0725">CVE-2025-0725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3715">CVE-2022-3715</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22871">CVE-2025-22871</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>cert-manager-cainjector</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45287">CVE-2023-45287</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45285">CVE-2023-45285</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44487">CVE-2023-44487</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39325">CVE-2023-39325</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39323">CVE-2023-39323</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29405">CVE-2023-29405</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29404">CVE-2023-29404</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29403">CVE-2023-29403</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29402">CVE-2023-29402</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29400">CVE-2023-29400</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24540">CVE-2023-24540</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24539">CVE-2023-24539</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24538">CVE-2023-24538</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24537">CVE-2023-24537</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24536">CVE-2023-24536</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24534">CVE-2023-24534</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41725">CVE-2022-41725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41724">CVE-2022-41724</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41723">CVE-2022-41723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41715">CVE-2022-41715</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32189">CVE-2022-32189</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30635">CVE-2022-30635</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30633">CVE-2022-30633</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30632">CVE-2022-30632</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30631">CVE-2022-30631</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30630">CVE-2022-30630</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30580">CVE-2022-30580</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2880">CVE-2022-2880</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2879">CVE-2022-2879</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28327">CVE-2022-28327</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28131">CVE-2022-28131</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27664">CVE-2022-27664</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24921">CVE-2022-24921</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24675">CVE-2022-24675</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23806">CVE-2022-23806</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23773">CVE-2022-23773</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23772">CVE-2022-23772</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44716">CVE-2021-44716</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41772">CVE-2021-41772</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41771">CVE-2021-41771</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39293">CVE-2021-39293</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38297">CVE-2021-38297</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33198">CVE-2021-33198</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33196">CVE-2021-33196</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33195">CVE-2021-33195</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33194">CVE-2021-33194</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29923">CVE-2021-29923</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27918">CVE-2021-27918</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28367">CVE-2020-28367</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28366">CVE-2020-28366</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28362">CVE-2020-28362</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16845">CVE-2020-16845</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>cert-manager-controller</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45287">CVE-2023-45287</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45285">CVE-2023-45285</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44487">CVE-2023-44487</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39325">CVE-2023-39325</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39323">CVE-2023-39323</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29405">CVE-2023-29405</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29404">CVE-2023-29404</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29403">CVE-2023-29403</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29402">CVE-2023-29402</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29400">CVE-2023-29400</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24540">CVE-2023-24540</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24539">CVE-2023-24539</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24538">CVE-2023-24538</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24537">CVE-2023-24537</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24536">CVE-2023-24536</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24534">CVE-2023-24534</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41725">CVE-2022-41725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41724">CVE-2022-41724</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41723">CVE-2022-41723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41715">CVE-2022-41715</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32189">CVE-2022-32189</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30635">CVE-2022-30635</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30633">CVE-2022-30633</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30632">CVE-2022-30632</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30631">CVE-2022-30631</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30630">CVE-2022-30630</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30580">CVE-2022-30580</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2880">CVE-2022-2880</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2879">CVE-2022-2879</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28327">CVE-2022-28327</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28131">CVE-2022-28131</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27664">CVE-2022-27664</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24921">CVE-2022-24921</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24675">CVE-2022-24675</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23806">CVE-2022-23806</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23773">CVE-2022-23773</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23772">CVE-2022-23772</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44716">CVE-2021-44716</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41772">CVE-2021-41772</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41771">CVE-2021-41771</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39293">CVE-2021-39293</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38297">CVE-2021-38297</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33198">CVE-2021-33198</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33196">CVE-2021-33196</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33195">CVE-2021-33195</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33194">CVE-2021-33194</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29923">CVE-2021-29923</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27918">CVE-2021-27918</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28367">CVE-2020-28367</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28366">CVE-2020-28366</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28362">CVE-2020-28362</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16845">CVE-2020-16845</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>cert-manager-webhook</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45287">CVE-2023-45287</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45285">CVE-2023-45285</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44487">CVE-2023-44487</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39325">CVE-2023-39325</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39323">CVE-2023-39323</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29405">CVE-2023-29405</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29404">CVE-2023-29404</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29403">CVE-2023-29403</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29402">CVE-2023-29402</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29400">CVE-2023-29400</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24540">CVE-2023-24540</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24539">CVE-2023-24539</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24538">CVE-2023-24538</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24537">CVE-2023-24537</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24536">CVE-2023-24536</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24534">CVE-2023-24534</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41725">CVE-2022-41725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41724">CVE-2022-41724</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41723">CVE-2022-41723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41715">CVE-2022-41715</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32189">CVE-2022-32189</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30635">CVE-2022-30635</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30633">CVE-2022-30633</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30632">CVE-2022-30632</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30631">CVE-2022-30631</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30630">CVE-2022-30630</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30580">CVE-2022-30580</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2880">CVE-2022-2880</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2879">CVE-2022-2879</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28327">CVE-2022-28327</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28131">CVE-2022-28131</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27664">CVE-2022-27664</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24921">CVE-2022-24921</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24675">CVE-2022-24675</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23806">CVE-2022-23806</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23773">CVE-2022-23773</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23772">CVE-2022-23772</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44716">CVE-2021-44716</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41772">CVE-2021-41772</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41771">CVE-2021-41771</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39293">CVE-2021-39293</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38297">CVE-2021-38297</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33198">CVE-2021-33198</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33196">CVE-2021-33196</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33195">CVE-2021-33195</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33194">CVE-2021-33194</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29923">CVE-2021-29923</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27918">CVE-2021-27918</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28367">CVE-2020-28367</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28366">CVE-2020-28366</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28362">CVE-2020-28362</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16845">CVE-2020-16845</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>vault</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0377">CVE-2025-0377</a> </li></ul></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<p><strong>Fixed since last minor release</strong></p>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>391923260</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24789">CVE-2024-24789</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45337">CVE-2024-45337</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45338">CVE-2024-45338</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24790">CVE-2024-24790</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23635">CVE-2022-23635</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31045">CVE-2022-31045</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39156">CVE-2021-39156</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39155">CVE-2021-39155</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14993">CVE-2019-14993</a> </li></ul></td>
</tr>
<tr>
<td><strong>391923260</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong>  (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>) <br/>This addresses the following vulnerabilities: <ul> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27788">CVE-2025-27788</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22869">CVE-2025-22869</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22868">CVE-2025-22868</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45337">CVE-2024-45337</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-CVE-2024-34158">CVE-2024-34158</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-CVE-2024-34156">CVE-2024-34156</a></li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6481">CVE-2023-6481</a></li> </ul></td>
</tr>
<tr>
<td><strong>385394193</strong>, <strong>383850393</strong>, <strong>383778273</strong></td>
<td><strong>Security fixes for <code>apigee-cassandra-backup-utility</code>, <code>apigee-cassandra-client</code>, and <code>apigee-hybrid-cassandra</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0727">CVE-2024-0727</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5678">CVE-2023-5678</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3715">CVE-2022-3715</a> </li></ul></td>
</tr>
<tr>
<td><strong>385394193</strong>, <strong>383850393</strong>, <strong>383778273</strong></td>
<td><strong>Security fixes for <code>apigee-cassandra-backup-utility</code>, <code>apigee-cassandra-client</code>, and <code>apigee-hybrid-cassandra</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1133">v1.13.3</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3715">CVE-2022-3715</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0727">CVE-2024-0727</a> </li> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5678">CVE-2023-5678</a> </li></ul></td>
</tr>
<tr>
<td><strong>383113773, 382967738</strong></td>
<td><strong>Fixed a vulnerability in PythonScript policy.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)</td>
</tr>
<tr>
<td><strong>365178914</strong></td>
<td><strong>Security fixes for <code>apigee-cassandra-backup-utility</code> and <code>apigee-hybrid-cassandra</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>) <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37920">CVE-2023-37920</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22869">CVE-2025-22869</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22868">CVE-2025-22868</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1133">v1.13.3</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24790">CVE-2024-24790</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24928">CVE-2025-24928</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24855">CVE-2025-24855</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0306">CVE-2025-0306</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56171">CVE-2024-56171</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55549">CVE-2024-55549</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22869">CVE-2025-22869</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56171">CVE-2024-56171</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24791">CVE-2024-24791</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22868">CVE-2025-22868</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45338">CVE-2024-45338</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45337">CVE-2024-45337</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22869">CVE-2025-22869</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22868">CVE-2025-22868</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29786">CVE-2025-29786</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22869">CVE-2025-22869</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22868">CVE-2025-22868</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45338">CVE-2024-45338</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mint-task-scheduler</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21587">CVE-2025-21587</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mint-task-scheduler</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24970">CVE-2025-24970</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47535">CVE-2024-47535</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mint-task-scheduler</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1133">v1.13.3</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47535">CVE-2024-47535</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1133">v1.13.3</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24790">CVE-2024-24790</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9192">CVE-2019-9192</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010023">CVE-2019-1010023</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010022">CVE-2019-1010022</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20796">CVE-2018-20796</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23015">CVE-2025-23015</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37920">CVE-2023-37920</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1133">v1.13.3</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9287">CVE-2024-9287</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22868">CVE-2025-22868</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1142">v1.14.2</a>)  <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1094">CVE-2025-1094</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0395">CVE-2025-0395</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1133">v1.13.3</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10979">CVE-2024-10979</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> (Fixed in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#hybrid_v1141">v1.14.1</a>)  <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45338">CVE-2024-45338</a> </li></ul></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>May 29, 2025</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#May_29_2025</id>
    <updated>2025-05-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#May_29_2025"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">v1.14.2</strong>
<h3>Announcement</h3>
<p>On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.</p>
<h3>Deprecated</h3>
<p>The Apigee Classic UI will be shutdown as of August 29, 2025.</p>
<p>This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.</p>
<p>To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing <a href="https://docs.cloud.google.com/apigee/docs/api-platform/fundamentals/ui-overview">UI overview</a>.</p>
<p>See <a href="https://docs.cloud.google.com/apigee/docs/deprecations/apigee-classic-ui">Apigee Classic UI shutdown</a> for details on shutdown dates and exception request.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 16, 2025</title>
    <id>tag:google.com,2016:apigee-hybrid-release-notes#May_16_2025</id>
    <updated>2025-05-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#May_16_2025"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">1.14.2-hotfix.1</strong>
<h3>Announcement</h3>
<h3 id="hybrid_1142-hotfix1">hybrid 1.14.2-hotfix.1</h3>
<p>On May 16, 2025 we released an updated version of the Apigee hybrid software, 1.14.2-hotfix.1.</p>
<aside class="special"><strong>Important:</strong><span> If your installation is already on Apigee hybrid v1.14.2, use the following procedure to apply this hotfix. If your installation is on 1.14.1 or older, follow the instructions in <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version 1.14</a>.</span></aside>
<h4 id="apply_this_hotfix_with_the_following_steps">Apply this hotfix with the following steps:</h4>
<ol>
<li><p>Download the <code>apigee-org</code> and <code>apigee-env</code> charts with the <code>1.14.2-hotfix.1</code> version tag:</p>
<pre class="devsite-terminal">
export CHART_REPO=oci://us-docker.pkg.dev/apigee-release/apigee-hybrid-helm-charts
<code class="devsite-terminal">export CHART_VERSION=1.14.2-hotfix.1</code>
<code class="devsite-terminal">helm pull $CHART_REPO/apigee-env --version $CHART_VERSION --untar</code>
<code class="devsite-terminal">helm pull $CHART_REPO/apigee-org --version $CHART_VERSION --untar</code>
</pre></li>
<li><p><b>Optional</b>: Perform this step if you need to allow use of the <code>allOf</code> combinator along with setting <code>additionalProperties: true</code> in your OAS spec. See <a href="#393615439">fixed bug 393615439</a>.</p>
<p>Add the following stanza to your <code>overrides.yaml</code>:</p>
<pre class="prettyprint"><code>runtime:
  cwcAppend:
    conf_message-processor-communication_oas.disable.resolve.combinator: true
</code></pre></li>
<li><p>Install the hotfix release:</p>
<ol>
<li><p>Update the <code>apigee-env</code> chart with the <code>helm upgrade</code> command and your current overrides file for each environment in your Apigee org:</p>
<h4><b>Dry run:</b></h4>
<pre class="devsite-terminal">
helm upgrade <var>ENV_RELEASE_NAME</var> apigee-env/ \
--namespace <var>APIGEE_NAMESPACE</var> \
--set env=<var>ENV_NAME</var> \
--atomic \
-f <var>OVERRIDES_FILE</var> \
--dry-run=server
</pre>
<ul>
<li><var>ENV_RELEASE_NAME</var> is a name used to keep track of installation and upgrades of the <code>apigee-env chart</code>. This name must be unique from the other Helm release names in your installation. Usually this is the same as <var>ENV_NAME</var>. However, if your environment has the same name as your environment group, you must use different release names for the environment and environment group, for example <code>dev-env-release</code> and <code>dev-envgroup-release</code>. For more information on releases in Helm, see <a href="https://helm.sh/docs/intro/using_helm/#three-big-concepts">Three big concepts</a> in the Helm documentation.</li>
<li><var>APIGEE_NAMESPACE</var> is your installation's namespace. The default is <code>apigee</code>.</li>
<li><var>ENV_NAME</var> is the name of the environment you are upgrading.</li>
<li><var>OVERRIDES_FILE</var> is your edited overrides file.</li>
</ul>
<h4><b>Install the changes:</b></h4>
<pre class="devsite-terminal">helm upgrade <var>ENV_RELEASE_NAME</var> apigee-env/ \
--namespace <var>APIGEE_NAMESPACE</var> \
--set env=<var>ENV_NAME</var> \
--atomic \
-f <var>OVERRIDES_FILE</var></pre></li>
<li><p>Update the <code>apigee-org</code> chart:</p>
<h4><b>Dry run:</b></h4>
<pre class="devsite-terminal">helm upgrade <var>ORG_NAME</var> apigee-org/ \
--namespace <var>APIGEE_NAMESPACE</var> \
-f <var>OVERRIDES_FILE</var> \
--dry-run=server</pre>
<h4><b>Install the changes:</b></h4>
<pre class="devsite-terminal">helm upgrade <var>ORG_NAME</var> apigee-org/ \
--namespace <var>APIGEE_NAMESPACE</var> \
-f <var>OVERRIDES_FILE</var></pre></li>
</ol></li>
<li><p>Verify the installation:</p>
<p>Ensure runtime and udca pods are up and running by checking their state:</p>
<p><pre class="devsite-terminal">kubectl -n APIGEE_NAMESPACE get pods -l app=apigee-runtime</pre>
<pre class="devsite-terminal">kubectl -n APIGEE_NAMESPACE get pods -l app=apigee-udca</pre></p></li>
</ol>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version 1.14</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a hotfix release: For critical security and other immediate fixes, Apigee provides specific container image tags that you must manually update in your existing deployments. The Helm chart binary usually remains unchanged for hotfixes. Hotfixes are temporary and their changes will be included in the next standard release. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td id="393615439"><b>393615439</b></td>
<td><b>OASValidation behavior for <code>allOf</code> with <code>additionalProperties: true</code>.</b>
<h4><b>Issue</b></h4>
<p>
          The OASValidation policy in Apigee Hybrid versions 1.12 and later may incorrectly reject requests when validating against an OpenAPI Specification (OAS) that uses combinator keywords (<code>allOf</code>, <code>oneOf</code>, <code>anyOf</code>) and allows additional properties (<code>additionalProperties: true</code>) within the combined schema. This occurs because the default behavior resolves combinators into an aggregated schema before validation, but an underlying issue in the parser library can cause the <code>additionalProperties</code> definition to be handled incorrectly during this resolution. This behavior differs from Apigee Edge and older Apigee Hybrid versions.
        </p>
<h4><b>Resolution</b></h4>
<p>
          A configuration flag has been introduced to control this behavior. By setting this flag, you can disable the pre-validation combinator resolution step, reverting to the behavior consistent with Apigee Edge and older Hybrid versions.
        </p>
<h4><b>Validation errors in Apigee hybrid</b></h4>
<p>
          If you encounter the validation errors described above, particularly for specs that worked correctly in Apigee Edge or Hybrid versions prior to 1.12, you can revert to the previous validation behavior by setting the following flag for the apigee-runtime container:
        </p>
<pre class="devsite-click-to-copy">conf_message-processor-communication_oas.disable.resolve.combinator = true</pre>
<aside class="note">
<b>Note:</b> Reverting to the older behavior (by setting the flag to true) reintroduces the older limitation: When using <code>allOf</code>, the <code>additionalProperties</code> keyword must be explicitly set to true if you intend to make the inheritance work correctly. The older behavior does not correctly handle schema validation with <code>allOf</code> when <code>additionalProperties</code> is set to false or is undefined. Customers migrating from Edge/OPDK or older hybrid versions should already be working around this limitation.
        </aside>
</td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Incorporated an updated base image for <code>stackdriver-logging-agent</code>, improving the overall security of the service.</strong> <br/>This addresses the following vulnerabilities (among others and not limited to): <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32221">CVE-2022-32221</a> </li> <li><a href="https://osv.dev/vulnerability/GHSA-jvgm-pfqv-887x">GHSA-jvgm-pfqv-887x</a> </li></ul></td>
</tr>
</tbody>
</table>
]]>
    </content>
  </entry>

</feed>
