v2.0.2
TanStack/routerv2.0.2Jun 5, 2026by ryancragun
AI Summary
A security and maintenance release addressing container compatibility and RSA key vulnerabilities, while updating dependencies and fixing UI bugs.
Key Highlights
- Limited RSA key sizes to 8192 bits to address CVE-2026-39829
- Removed `cap_ipc_lock` capability for container runtime compatibility
- Updated Azure enterprise plugin to v0.26.4+ent
- Fixed plugin signature verification with expired PGP keys
- Fixed UI transit key version dropdown state
Breaking Changes
- Removed `cap_ipc_lock` capability on `vault` at build time (requires `disable_mlock = true` in config)
- RSA key sizes limited to a maximum of 8192 bits
Full Release Notes
BREAKING CHANGES: * containers: Remove `cap_ipc_lock` capability on `vault` at build time to allow running Vault in common container runtimes. Vault in containers will no longer be able to call `mlock()` to lock memory. Operators should set `disable_mlock = true` in Vault's configuration. Runtime operators are advised to disable swapping to guarantee data safety. * secrets/ssh: RSA key sizes are now limited to a maximum size of 8192 bits addressing CVE-2026-39829 CHANGES: * core: Bump Go version to 1.26.4 * secrets/azure (enterprise): Update plugin to [v0.26.4+ent](https://github.com/hashicorp/vault-plugin-secrets-azure-enterprise/releases/tag/v0.26.4+ent) BUG FIXES: * plugins: Fix plugin signature verification failure with expired pgp key when registering a plugin. * ui/transit: Fix key version dropdown selected state when editing a transit key.