Each GKE attached clusters release comes with Kubernetes version notes. These are similar to release notes but are specific to a Kubernetes version and may offer more technical detail.
GKE attached clusters supports the following Kubernetes versions:
Kubernetes 1.35
1.35.0-gke.1
- Security Fixes
- Fixed CVE-2024-24791
- Fixed CVE-2024-34155
- Fixed CVE-2024-34156
- Fixed CVE-2024-34158
- Fixed CVE-2024-35255
- Fixed CVE-2024-45337
- Fixed CVE-2024-51744
- Fixed CVE-2025-14831
- Fixed CVE-2025-15467
- Fixed CVE-2025-22868
- Fixed CVE-2025-22869
- Fixed CVE-2025-22872
- Fixed CVE-2025-30204
- Fixed CVE-2025-54410
- Fixed CVE-2025-68160
- Fixed CVE-2025-69418
- Fixed CVE-2025-69419
- Fixed CVE-2025-69420
- Fixed CVE-2025-69421
- Fixed CVE-2025-9820
- Fixed CVE-2026-2003
- Fixed CVE-2026-2004
- Fixed CVE-2026-2005
- Fixed CVE-2026-2006
- Fixed CVE-2026-22795
- Fixed CVE-2026-22796
Kubernetes 1.34
1.34.0-gke.2
- Security Fixes
- Fixed CVE-2024-24791
- Fixed CVE-2024-34155
- Fixed CVE-2024-34156
- Fixed CVE-2024-34158
- Fixed CVE-2024-35255
- Fixed CVE-2024-45337
- Fixed CVE-2024-51744
- Fixed CVE-2025-14831
- Fixed CVE-2025-15467
- Fixed CVE-2025-22868
- Fixed CVE-2025-22869
- Fixed CVE-2025-22872
- Fixed CVE-2025-30204
- Fixed CVE-2025-54410
- Fixed CVE-2025-68160
- Fixed CVE-2025-69418
- Fixed CVE-2025-69419
- Fixed CVE-2025-69420
- Fixed CVE-2025-69421
- Fixed CVE-2025-9820
- Fixed CVE-2026-2003
- Fixed CVE-2026-2004
- Fixed CVE-2026-2005
- Fixed CVE-2026-2006
- Fixed CVE-2026-22795
- Fixed CVE-2026-22796
1.34.0-gke.1
Breaking Change: GKE attached clusters no longer validate that the
anthos.googleapis.comservice is enabled when creating or updating a cluster. Attached clusters are now included in the GKE Standard tier, so this validation is no longer required.Feature: The Connect Agent for Attached clusters now uses the
svc.id.googworkload identity pool by default. You don't need to take any action because the agent is automatically authorized on the server side.Security Fixes
- Fixed CVE-2025-12817
- Fixed CVE-2025-12818
- Fixed CVE-2025-9230
- Fixed CVE-2025-9232
Kubernetes 1.33
1.33.0-gke.3
- Security Fixes
- Fixed CVE-2024-24791
- Fixed CVE-2024-34155
- Fixed CVE-2024-34156
- Fixed CVE-2024-34158
- Fixed CVE-2024-35255
- Fixed CVE-2024-45337
- Fixed CVE-2024-51744
- Fixed CVE-2025-14831
- Fixed CVE-2025-15467
- Fixed CVE-2025-22868
- Fixed CVE-2025-22869
- Fixed CVE-2025-22872
- Fixed CVE-2025-30204
- Fixed CVE-2025-54410
- Fixed CVE-2025-68160
- Fixed CVE-2025-69418
- Fixed CVE-2025-69419
- Fixed CVE-2025-69420
- Fixed CVE-2025-69421
- Fixed CVE-2025-9820
- Fixed CVE-2026-2003
- Fixed CVE-2026-2004
- Fixed CVE-2026-2005
- Fixed CVE-2026-2006
- Fixed CVE-2026-22795
- Fixed CVE-2026-22796
1.33.0-gke.2
Breaking Change: GKE attached clusters no longer validate that the
anthos.googleapis.comservice is enabled when creating or updating a cluster. Attached clusters are now included in the GKE Standard tier, so this validation is no longer required.Security Fixes
- Fixed CVE-2025-12817
- Fixed CVE-2025-12818
- Fixed CVE-2025-9230
- Fixed CVE-2025-9232
1.33.0-gke.1
- Security Fixes
- Fixed CVE-2025-32988
- Fixed CVE-2025-32989
- Fixed CVE-2025-32990
- Fixed CVE-2025-3576
- Fixed CVE-2025-4802
- Fixed CVE-2025-6395
- Fixed CVE-2025-8713
- Fixed CVE-2025-8714
- Fixed CVE-2025-8715