k3s v1.37.0+k3s1 released on 14-09-2026

k3s v1.37.0+k3s1 is out now. It upgrades the embedded Kubernetes to v1.37.0 and includes multiple bundled component bumps and security hardening, which benefits operators who need up-to-date APIs, fixes and image updates.
See the k3s GitHub release notes, the upstream Kubernetes v1.37 release notes for API and feature changes, or the k3s documentation for full details and upgrade guidance.
What’s in this release
- Upgrades embedded Kubernetes to v1.37.0 and updates bundled components (Kine v0.17.0, SQLite 3.53.4, Etcd v3.7.1-k3s1, Containerd v2.3.4-k3s1, runc v1.4.2, Flannel v0.28.4, Metrics-server v0.9.0, Traefik v3.7.13, CoreDNS v1.14.7, Helm-controller v0.17.7, Local-path-provisioner v0.0.37).
- Security and hardening fixes, including bumping google.golang.org/grpc to v1.83.2 to address CVE-2026-84445 and fixes for etcd client locking and node password informer sync.
- Operational improvements such as a new –write-kubeconfig-name server flag to set custom kubeconfig names, avoiding redundant image retagging for system-default-registry (fixes airgap import duplicate errors), and certificate fixes to include –advertise-address in apiserver SANs.
Upgrade notes
- There are upstream API and feature changes with Kubernetes v1.37 — review the upstream Kubernetes v1.37 release notes before upgrading for any API compatibility work.
- No special rollback instructions are provided in the release notes; apply your standard cluster rollback procedures if you need to revert.
If you try v1.37.0+k3s1, share feedback on the k3s GitHub issue tracker or join the project Slack to report your experience and any regressions.
