gcp Google Cloud release notes ·

Apigee hybrid v1.16.10 Released with Security Fixes and Kubernetes 1.36 Support

securityazuregcpgasecurity-advisoryengineergcp-gke
security feature patch announcement

Google Cloud has released Apigee hybrid v1.16.10, a patch update on September 17, 2026. This version includes critical security updates, addressing multiple CVEs and vulnerabilities in policies like ValidateSAMLAssertion, Script, and OAuthV2. It also adds support for Kubernetes 1.36 across various platforms and introduces forward proxy capabilities for AI policies. These updates enhance security, improve stability, and expand deployment flexibility for Apigee hybrid users.

  • Kubernetes 1.36 support
  • Forward proxy support for AI policies
  • v1.16.10
Security (1)
  • Apigee hybrid

    Bug ID Description N/A Security fixes for apigee-asm-ingress . This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864 CVE-2026-56865 GHSA-hrxh-6v49-42gf N/A Security fixes for apigee-asm-istiod . This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864 CVE-2026-56865 GHSA-hrxh-6v49-42gf N/A Security fixes for apigee-connect-agent . This addresses the following vulnerabilities:

Features (2)
  • Apigee hybrid Kubernetes 1.36 support

    Kubernetes 1.36 support Apigee hybrid v1.16.10 adds support for Kubernetes 1.36 on Google Kubernetes Engine (GKE), Google Distributed Cloud Virtual for VMware (vSphere), Google Distributed Cloud Virtual for bare metal, Amazon EKS, Azure AKS, and Rancher Kubernetes Engine (RKE2). For more information, see Supported platforms .

  • Apigee hybrid Forward proxy support for AI policies

    Forward proxy support for AI policies Apigee hybrid v1.16.10 adds forward proxy support for AI policies, such as the Model Armor and semantic caching policies. Outbound calls from these policies can now be routed through an HTTP forward proxy. For more information, see Configure a forward proxy , Get started with the Model Armor policies , and Get started with semantic caching policies .

Fixes (1)
  • Apigee hybrid

    Fixed in this release Bug ID Description 556750755 Fixed an issue where EventFlow (Server-Sent Events) dropped or truncated events following a large (>16 KB) event under load on the http-adaptor datapath. 547712217 Fixed an issue where EventFlow (Server-Sent Events) responses larger than 16 KB could be truncated or corrupted across socket reads. 519729209 Fixed a SAML XML Signature Wrapping (XSW) vulnerability in the ValidateSAMLAssertion policy. 514384893 Hardened the Script policy to block server-side request forgery (SSRF) to link-local addresses. 505645076 Fixed a security issue in the

Notes (1)
  • Apigee hybrid v1.16.10

    On September 17, 2026 we released an updated version of the Apigee hybrid software, v1.16.10. For information on upgrading, see Upgrading Apigee hybrid to version v1.16.10 . For information on new installations, see The big picture . Note: This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see Apigee release process .

Read the original announcement →

https://docs.cloud.google.com/release-notes#September_17_2026

Related releases