Notes
🛡️ Security updates
- Updated
google.golang.org/grpcto 1.83.1 to resolve security vulnerability CVE-2026-84304 in #2328
🐞 Bug fixes
- Allowed mount path validation during safe directory checks #2325
Support statement:
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent.
We recommend updating to the latest agent version as soon as it's available. If you can't upgrade to the latest version, update your agents to a version no more than 90 days old. Read more about keeping agents up to date.
See the New Relic Infrastructure agent EOL policy for information about agent releases and support dates.
Notes
🛡️ Security notices
- Updated
flexto version v1.18.12 to resolve security vulnerability CVE-2026-56854 in #2323
Support statement:
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent.
We recommend updating to the latest agent version as soon as it's available. If you can't upgrade to the latest version, update your agents to a version no more than 90 days old. Read more about keeping agents up to date.
See the New Relic Infrastructure agent EOL policy for information about agent releases and support dates.
Notes
🛡️ Security notices
- Bumped http://golang.org/x/crypto to v0.55.0 fix security CVE-2026-56854 in #2321
🐞 Bug fixes
- Extended the WMI fallback to retrieve Queue Length in #2312
- Retry Start-Service on SCM races and validate license key before starting in #2307
Support statement:
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent.
We recommend updating to the latest agent version as soon as it's available. If you can't upgrade to the latest version, update your agents to a version no more than 90 days old. Read more about keeping agents up to date.
See the New Relic Infrastructure agent EOL policy for information about agent releases and support dates.
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent. New Relic recommends that you upgrade the agent regularly and at a minimum every 3 months. As of this release, the oldest supported version is Infrastructure agent 1.65.3.
Changed
- Added Azure Key Vault as another databind secret source. #2304
- Fixed a local privilege escalation vulnerability caused by predictable Fluent Bit config directory reuse. #2306
- Bumped Go to 1.26.6 to fix multiple Go stdlib CVEs. #2308
- Updated embedded OHI versions (
nri-docker,nri-flex,nri-winservices,nri-prometheus) to fix CVEs. #2316
Notes
🛡️ Security notices
- Fixed a remote code execution vulnerability caused by path traversal in #2292
- Added explicit permissions to GitHub Actions workflows to reduce token scope in #2232
- Bumped google.golang.org/grpc from 1.79.3 to 1.82.1 in go.mod in #2296
- Bumped embedded OHI versions (nri-docker, nri-flex) to fix known CVEs in #2302
- bump vulnerable dependencies flagged by Trivy scan in #2301
🚀 Enhancements
- Added support for ignoring default integration locations via disable_plugin_default_dir_scan in #2290
- Made environment variables used by Agent Control public in #2293
- Added OCI tag support to match AWS tags (Phase 1 + Phase 2) in #2295
- Enabled NRIA_DISABLE_PLUGIN_DEFAULT_DIR_SCAN by default for Agent-Control-managed agents in #2300
- Removed nri-flex from agent-control artifacts in #2291
🐞 Bug fixes
- Restored missing job permissions for release and canary workflows in #2303
Support statement:
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent.
We recommend updating to the latest agent version as soon as it's available. If you can't upgrade to the latest version, update your agents to a version no more than 90 days old. Read more about keeping agents up to date.
See the New Relic Infrastructure agent EOL policy for information about agent releases and support dates.
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent. New Relic recommends that you upgrade the agent regularly and at a minimum every 3 months. As of this release, the oldest supported version is Infrastructure agent 1.65.3.
Changed
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent. New Relic recommends that you upgrade the agent regularly and at a minimum every 3 months. As of this release, the oldest supported version is Infrastructure agent 1.65.3.
Changed
- Fixed a panic condition caused by a double close operation. 2270
- Fixed the local server binding behavior to default strictly to localhost. 2271
- Dependency updates:
- Updated
newrelic/nri-flextov1.18.8. #2278 - Updated
newrelic/nri-winservicestov1.5.3. #2279 - Updated
newrelic/nri-prometheustov2.29.4. #2276 - Updated
newrelic/nri-dockertov2.8.1. #2277 - Updated the core agent dependency to
v1.26.5. #2275 - Updated
newrelic-fluent-bit-outputtov3.7.0(Linux) to resolve security vulnerabilities CVE-2026-39820, CVE-2026-42499, CVE-2026-33814, CVE-2026-42501, CVE-2026-33811, and CVE-2026-42504. #2280
- Updated
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent. New Relic recommends that you upgrade the agent regularly and at a minimum every 3 months. As of this release, the oldest supported version is Infrastructure agent 1.65.1.
Changed
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent. New Relic recommends that you upgrade the agent regularly and at a minimum every 3 months. As of this release, the oldest supported version is Infrastructure agent 1.65.1.
Changed
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent. New Relic recommends that you upgrade the agent regularly and at a minimum every 3 months. As of this release, the oldest supported version is Infrastructure agent 1.65.0.