This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.37 minor version.
These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:
- Product updates: GKE release notes
- Security vulnerabilities: Security bulletins
1.37.0-gke.2941000
The following sections describe changes in this patch version when compared with the previous patch version, 1.37.0-gke.2155000. For information about upstream Kubernetes changes, see the Kubernetes v1.37.0 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
customer-logs-exporter
Updated customer-logs-exporter component from version 1.36.0-gke.10 to 1.36.0-gke.11.
- Security Fixes:
- Updated
google.golang.org/grpcto v1.82.1 to resolve GO-2026-6061.
- Updated
- Miscellaneous:
- Introduced new configuration support for cloud logging endpoints and project-specific metadata via
ComponentOptionsConfig.
- Introduced new configuration support for cloud logging endpoints and project-specific metadata via
gke-metrics-agent
Updated gke-metrics-agent component from version 2.137.1-gke.0 to 2.137.3-gke.0.
- Features:
- Implemented node-daemon Pressure Stall Information (PSI) collection.
- Miscellaneous:
- Optimized the container image size by refining vendor dependencies.
- Updated Workload Autoscaler to version 0.28.0-gke.3.
gvisor
Updated gvisor component from version 1.37.7 to 1.37.11.
- Miscellaneous:
- Updated gVisor to version 20260727.0_RC04.
l7-lb-controller-combined
Updated l7-lb-controller-combined component from version 1.41.1-gke.0 to 1.41.3-gke.0.
- Bug Fixes:
- Improved L4 Address Manager IP validation to prevent false positive substring matches and enforce explicit Network Tier and Load Balancing Scheme validation.
- Security Fixes:
- Go version update to 1.26.6, Go kubernetes client dependency updates to v1.36.3, update google.golang.org/api and google.golang.org/grpc to the newest versions.
1.37.0-gke.2155000
The following sections describe changes in this patch version when compared with the previous patch version, 1.36.3-gke.1767000. For information about upstream Kubernetes changes, see the Kubernetes v1.37.0 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
accelerator-operator
Updated accelerator-operator component from version 1.35.1 to 1.35.3.
- Security Fixes:
- Updated
go.opentelemetry.io/otel/sdkto v1.40.0 to resolve GO-2026-4394. - Updated
golang.org/x/netto v0.53.0 to resolve GO-2026-4440, GO-2026-4559, and GO-2026-4918. - Updated
google.golang.org/grpcto v1.79.3 to resolve GO-2026-4762.
- Updated
- Miscellaneous:
- Updated base images to use Golang 1.25.10.
- Backported CI/CD configurations, container build steps, and Go 1.25.0 toolchain fixes to the release branch.
- Updated the component image to version 1.35.0-gke.8.
advanceddatapath
Updated advanceddatapath component from version 36.3.14 to 36.4.2.
- Miscellaneous:
- Added node tolerations for
kubernetes.io/arch: arm64to allow component pods to be scheduled on ARM64-based nodes with theNoScheduleeffect.
- Added node tolerations for
customer-logs-exporter
Updated customer-logs-exporter component from version 1.36.0-gke.9 to 1.36.0-gke.10.
- Security Fixes:
- Updated
google.golang.org/grpcto v1.82.1 to resolve GO-2026-6061.
- Updated
filestorecsi
Updated filestorecsi component from version 1.36.17 to 1.36.18.
- Miscellaneous:
- Updated the Go runtime to version 1.25.11.
- Updated base images to the latest distroless versions for improved security and stability.
- Explicitly named an internal initialization container as
imgSpnpInitContainerin the component manifest.
gcp-controller-manager-combined
Updated gcp-controller-manager-combined component from version 36.1.4 to 36.1.6.
- Features:
- Added support for the
ToLocalhosttype within the component configuration.
- Added support for the
- Miscellaneous:
- Renamed the custom signerName delegation flag to
allow-signing-kubelet-serving-for-non-gcpto improve clarity for signing kubelet serving certificates on non-GCP nodes.
- Renamed the custom signerName delegation flag to
gcsfusecsi
Updated gcsfusecsi component from version 1.36.41 to 1.37.3.
- Features:
- Introduced shared mount feature support for non-production environments.
- Added
csi-attachercomponent support, including associatedPriorityClassand RBAC configurations for non-production environments.
- Bug Fixes:
- Renamed the controller flag
--leader-election-namespaceto--driver-namespaceto correctly reflect its function. - Allow ToLocalhost egress in StaticPodNetworkPolicy for gcsfusecsi-controller to prevent SPNP firewall drops during local OAuth token exchange.
- Renamed the controller flag
- Security Fixes:
- Remediated security vulnerability GHSA-gcjh-h69q-9w9g by upgrading
github.com/google/cel-goto v0.29.0. - Updated
github.com/google/cel-goto resolve GO-2026-6094. - Updated
go.etcd.io/etcd/client/pkg/v3to resolve GO-2026-6107. - Updated the Go base image and the
csi-attachersidecar container to address security vulnerabilities.
- Remediated security vulnerability GHSA-gcjh-h69q-9w9g by upgrading
- Miscellaneous:
- Updated mount configurations to utilize distinct host paths for pods and plugin registration (
kubelet-pods-dirandkubelet-plugins-dir). - Updated the
addonmanager.kubernetes.io/modefrom Reconcile to Recreate.
- Updated mount configurations to utilize distinct host paths for pods and plugin registration (
gvisor
Updated gvisor component from version 1.36.19 to 1.37.7.
- Miscellaneous:
- Updated gVisor to version 20260803.0_RC01.
managed-prometheus
Updated managed-prometheus component from version 0.18.2-gke.0 to 0.19.0-gke.1.
- Features:
- Fixed various vulnerabilities including frontend rules and alerts API missing auth
- Added default PSI metrics (
container_pressure_*) in the cAdvisor scrape configuration.
osimage
Updated osimage component from version 1.36.75 to 1.36.79.
- Features:
- cchost: Added
bpf-lsm-policyfor enhanced VM restrictions. - Updated Linux kernel to COS-6.12.94.
- Updated Docker to v27.5.1.
- Updated Containerd to v2.2.6.
- cchost: Added
- Security Fixes:
- Fixed CVE-2026-64244, CVE-2026-64247, CVE-2026-64253, CVE-2026-64265, CVE-2026-64266, CVE-2026-64284, CVE-2026-64289, CVE-2026-64294, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64313, CVE-2026-64317, CVE-2026-64319, CVE-2026-64320, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64354, CVE-2026-64355, CVE-2026-64357, CVE-2026-64368, CVE-2026-64370, CVE-2026-64373, CVE-2026-64378, CVE-2026-64379, CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64414, CVE-2026-64415, CVE-2026-64418, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64432, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64456, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64512, CVE-2026-64514, and CVE-2026-64556 in the Linux kernel.
- Fixed CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598 in dev-go/crypto.
- Fixed CVE-2026-58055 by upgrading net-libs/nghttp2 to 1.69.0.
- Fixed CVE-2026-58470 in net-misc/wget.
- Fixed CVE-2026-59890 in dev-python/setuptools.
- Miscellaneous:
- Adjusted runtime sysctl configuration for
net.ipv4.udp_mem.
- Adjusted runtime sysctl configuration for