Views
5

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

Update Summary

Apigee released 1-17-0-apigee-7 on 2026-05-12 with broad infrastructure security fixes, OAuthV2 and policy hardening, and stability improvements. API hub also added MCP tools support for agentic AI workflows in Public Preview.

Update Details

Security

  • Security fix for Apigee infrastructure addressing multiple vulnerabilities, including CVE-2026-42587, CVE-2026-5588, CVE-2026-34480, GHSA-72hv-8253-57qq, CVE-2026-33870, CVE-2026-33871, CVE-2026-35611, CVE-2026-33170, CVE-2026-33169, CVE-2026-33176, CVE-2026-33210, CVE-2026-33186, CVE-2026-42499, CVE-2026-35469, CVE-2026-32281, and CVE-2026-27144.
  • Improved XML processing security to prevent external entity injection.
  • Improved security in OAuthV2 policy and fixed unauthorized token injection.
  • Improved security isolation for PythonScript policy execution.
  • Improved security policy resolution so custom security policies apply correctly.
  • Improved IPv4 address normalization for consistent access control evaluation.
  • Hardened message processor management ports by blocking external access to internal management endpoints.
  • Improved input validation in AI protection policies to prevent Server-Side Request Forgery.
  • Improved SAML assertion validation.
  • Added enforcement for product association in OAuthV2 flow so apps without valid products are denied.
  • A vulnerability in AMD firmware affecting SEV-SNP guests was addressed in Compute Engine: CVE-2025-61971, CVE-2025-61972, CVE-2024-36315.
  • A vulnerability in Zen 2 microarchitecture processors affecting the micro-operation cache was addressed in Compute Engine: CVE-2025-54518.

Bug Fixes

  • Fixed a concurrency issue to improve stability under high load.
  • Fixed content-length header handling in external processing to prevent incorrect values.
  • Improved performance while listing apps at scale.
  • Fixed recurring fee calculation in monetization to correctly apply rate plan overrides.
  • Fixed streaming response handling to prevent race conditions in bidirectional flows.
  • Fixed preservation of client request IDs during proxy chaining.
  • Fixed SpikeArrest policy edge cases that previously caused 500 errors.
  • Gracefully handled forward proxy connection failures to avoid retry storms, excessive CPU usage, and unnecessary scaling.
  • Fixed SSE streaming detection logic.
  • Improved performance and reduced redundant work in ingress status watcher.
  • Fixed a permanent difference in Config Connector ContainerCluster.databaseEncryption.state and added support for ALL_OBJECTS_ENCRYPTION_ENABLED.
  • Updated Config Connector MemorystoreInstance controller to use change cookies for better reconciliation stability and correctness.
  • Upgraded sys-apps/makedumpfile to v1.7.9 in Container Optimized OS.

New Features

  • API hub now exposes read-only APIs as Model Context Protocol (MCP) tools for agentic AI workflows in Public Preview.
  • BigQuery added AI.COUNT_TOKENS to estimate token counts for text input in Preview.
  • BigQuery generative AI functions can now expose token breakdowns by modality, including input, output, thought, and cache tokens, in Preview.
  • Cloud Database Migration Service now offers Gemini-powered conversion quality assessments for heterogeneous migrations in GA.
  • Config Connector 1.150.0 adds new alpha resources: GKEHubScope and CloudDeployTarget.
  • Config Connector adds new fields for CertificateManagerCertificate, ContainerCluster, and ContainerNodePool.
  • Config Connector improved resource creation logging with structured diffs.
  • Gemini Enterprise now supports GitLab data stores in Public Preview.
  • Google SecOps SIEM added relative and absolute time range selection for searches.
  • BigQuery Connector for SAP version 2.14 is now GA.

Hints

  • Apigee rollout began on 2026-05-12 and may take four or more business days to complete across Google Cloud zones.
  • Some Apigee features and fixes may not be available until rollout completion.
  • Config Connector direct reconciliation is opt-in and requires the cnrm.cloud.google.com/reconciler: direct annotation.
  • Cloud SQL commands for upgrading to the new network architecture have been re-enabled for MySQL, PostgreSQL, and SQL Server.
  • BigQuery Connector for SAP version 2.14 assigns configuration tables to authorization group ZSGC; user roles must include authorization for this group to retain access.
  • Google SecOps SIEM time range changes are rolling out from 2026-05-12 to 2026-05-18.
Product Information

Vendor: Google

Product: Cloud

Product type: Other

Platform: Web

Version: 1-17-0-apigee-7

Vendor release date: May 12, 2026

Published on updatealert.io: Jun 4, 2026

Description: Cloud platform for compute, data, networking, and developer services.