Cloud Service Mesh Receives Security Updates and New Tracing Feature
Google has released new versions of Cloud Service Mesh, including 1.29.7-asm.2, 1.28.10-asm.24, and 1.27.9-asm.34, which are now available for in-cluster deployments. These updates primarily resolve security vulnerabilities detailed in Security Bulletin GCP-2026-057, addressing various CVEs across the different versions. Additionally, the Rapid release channel now supports configuring the trace sampling rate using randomSamplingPercentage with the Telemetry API for clusters utilizing the TRAFFIC_DIRECTOR implementation. Users are advised to review the upgrade documentation to implement these critical security patches and leverage the new tracing capability.
- →1.29.7-asm.2 is now available for in-cluster Cloud Service Mesh.
- →1.28.10-asm.24 is now available for in-cluster Cloud Service Mesh.
- →1.27.9-asm.34 is now available for in-cluster Cloud Service Mesh.
Features (1) ›
- Cloud Service Mesh
For clusters using the TRAFFIC_DIRECTOR implementation, configuring the trace sampling rate with randomSamplingPercentage with the Telemetry API is now supported in the Rapid release channel. For more information, see Accessing Cloud Trace .
Fixes (3) ›
- Cloud Service Mesh
Patch 1.29.7-asm.2 contains the fix for the following platform CVEs: CVE Proxy Control Plane Distroless CNI Severity CVE-2026-5704 Yes Yes No Yes Medium (5.5)
- Cloud Service Mesh
Patch 1.28.10-asm.24 contains the fix for the following platform CVEs: CVE Proxy Control Plane Distroless CNI Severity CVE-2026-5704 Yes Yes No Yes Medium (5.5)
- Cloud Service Mesh
Patch 1.27.9-asm.34 contains fixes for the following platform CVEs: CVE Proxy Control Plane Distroless CNI Severity CVE-2026-10536 Yes Yes No Yes Low (9.8) CVE-2026-42151 No No No Yes High (7.5) CVE-2026-42154 No No No Yes High (7.5) CVE-2026-40179 No No No Yes Medium (6.1) CVE-2026-44903 No No No Yes Medium (6.1) CVE-2026-5704 Yes Yes No Yes Medium (5.5)
Notes (3) ›
- Cloud Service Mesh 1.29.7-asm.2 is now available for in-cluster Cloud Service Mesh.
1.29.7-asm.2 is now available for in-cluster Cloud Service Mesh. For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh . Cloud Service Mesh 1.29.7-asm.2 uses Envoy v1.35.14. This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057 .
- Cloud Service Mesh 1.28.10-asm.24 is now available for in-cluster Cloud Service Mesh.
1.28.10-asm.24 is now available for in-cluster Cloud Service Mesh. For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh . Cloud Service Mesh 1.28.10-asm.24 uses Envoy v1.36.10. This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057 .
- Cloud Service Mesh 1.27.9-asm.34 is now available for in-cluster Cloud Service Mesh.
1.27.9-asm.34 is now available for in-cluster Cloud Service Mesh. For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh . Cloud Service Mesh 1.27.9-asm.34 uses Envoy v1.35.14. This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057 .
https://docs.cloud.google.com/release-notes#August_26_2026
Related releases
- Google Cloud Compute Engine now Generally Available for Oracle workloads Google Cloud release notes ·
- GKE Gateway adds identity-based access control with GCPAuthzPolicy & GCPAuthzExtension Google Cloud release notes ·
- Cloud Monitoring: Ops Agent VM Extension Manager Policies are GA Google Cloud release notes ·
- Knowledge Catalog adds metadata import support for dbt Core and MetricFlow Google Cloud release notes ·
- Cloud Logging Ops Agent VM Extension Manager Policies are Now Generally Available Google Cloud release notes ·
- Google details dynamic capacity management strategies for AI infrastructure Google Cloud Blog ·