# Hotfixes for Version 2.22

This section provides details on all hotfixes available for version 2.22. Hotfixes are critical updates released between our major and minor versions to address specific issues or vulnerabilities. These updates ensure the system remains secure, stable, and optimized without requiring a full version upgrade.

<table><thead><tr><th width="116.0390625">Version</th><th width="125.2578125">Date (MM/DD/YYYY)</th><th width="117.01171875">Internal ID</th><th width="394.99609375">Description</th></tr></thead><tbody><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-34624</td><td>Fixed an issue in Projects and Departments where GPU utilization/allocation metrics were not displayed if only partial data was available.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-36512</td><td>Fixed a security vulnerability related to CVE-2025-64756 with severity HIGH.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-36443</td><td>Fixed an issue where the dashboard returned a 500 error instead of an informative error message.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-36493</td><td>Fixed a security vulnerability related to GHSA-43fc-jf86-j433 with severity HIGH.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-36598</td><td>Fixed an issue where department data was not synced to the cluster, affecting both department creation and updates.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-36680</td><td>Fixed a security vulnerability related to GHSA-pwhc-rpq9-4c8w with severity HIGH.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-36732</td><td>Fixed a security vulnerability related to GHSA-5vv4-hvf7-2h46 with severity HIGH.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-37170</td><td>Fixed a security vulnerability related to GHSA-23c5-xmqv-rm74 with severity HIGH.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-37174</td><td>Fixed a security vulnerability related to GHSA-72hv-8253-57qq with severity HIGH.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-37278</td><td>Fixed a security vulnerability related to CVE-2024-1013 with severity HIGH.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-37372</td><td>Fixed a security vulnerability related to CVE-2025-61731 with severity HIGH.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-37504</td><td>Fixed a security vulnerability related to CVE-2026-25679 with severity HIGH.</td></tr><tr><td>2.22.96</td><td>03/30/2026</td><td>RUN-37889</td><td>Fixed a security vulnerability related to GHSA-p77j-4mvh-x3m3 with severity HIGH.</td></tr><tr><td>2.22.93</td><td>02/15/2026</td><td>RUN-36555</td><td>Fixed a security vulnerability related to CVE-2024-56171 with severity HIGH.</td></tr><tr><td>2.22.92</td><td>02/12/2026</td><td>RUN-36380</td><td>Fixed a security vulnerability related to GHSA-pwhc-rpq9-4c8w with severity HIGH.</td></tr><tr><td>2.22.92</td><td>02/12/2026</td><td>RUN-36381</td><td>Fixed a security vulnerability related to GHSA-jmp9-x22r-554x with severity HIGH.</td></tr><tr><td>2.22.92</td><td>02/12/2026</td><td>RUN-36382</td><td>Fixed a security vulnerability related to GHSA-cv78-6m8q-ph82 with severity HIGH.</td></tr><tr><td>2.22.92</td><td>02/12/2026</td><td>RUN-36413</td><td>Fixed a security vulnerability related to CVE-2024-41110 with severity HIGH.</td></tr><tr><td>2.22.92</td><td>02/12/2026</td><td>RUN-36414</td><td>Fixed a security vulnerability related to CVE-2025-14459 and CVE-2025-64324 with severity HIGH.</td></tr><tr><td>2.22.92</td><td>02/12/2026</td><td>RUN-36457</td><td>Fixed an issue where, on rare occasions, "Allocation ratio by node pool" widget would show incorrect data.</td></tr><tr><td>2.22.91</td><td>02/03/2026</td><td>RUN-35326</td><td>Fixed an issue where the Projects/Departments table in the Overview dashboard sometimes showed fewer than 15 projects/departments when their workloads did not have allocated GPUs or were not in Running or Pending status.</td></tr><tr><td>2.22.90</td><td>01/26/2026</td><td>RUN-35976</td><td>Fixed an issue where workloads submitted with names longer than 63 characters failed to schedule.</td></tr><tr><td>2.22.87</td><td>01/26/2026</td><td>RUN-35443</td><td>Fixed a security vulnerability related to CVE-2025-68973 with severity HIGH.</td></tr><tr><td>2.22.86</td><td>01/25/2026</td><td>RUN-35922</td><td>Fixed a security vulnerability related to CVE-2026-0861 with severity HIGH.</td></tr><tr><td>2.22.79</td><td>01/20/2026</td><td>RUN-35421</td><td>Fixed a security vulnerability related to CVE-2025-15284 with severity HIGH.</td></tr><tr><td>2.22.79</td><td>01/20/2026</td><td>RUN-35637</td><td>Fixed an issue where, when CPU quota and Limit projects from exceeding department quota were both enabled, updating department or project memory quotas to very large values failed with incorrect validation errors, even though the values were valid.</td></tr><tr><td>2.22.74</td><td>01/13/2026</td><td>RUN-32181</td><td>Fixed a security vulnerability related to CVE-2025-32988 with severity HIGH.</td></tr><tr><td>2.22.74</td><td>01/13/2026</td><td>RUN-34607</td><td>Fixed issues where readiness probes did not work correctly with serving port authorization in single-node Knative inference workloads.</td></tr><tr><td>2.22.74</td><td>01/13/2026</td><td>RUN-34720</td><td>Fixed a security vulnerability related to CVE-2025-65637 with severity HIGH.</td></tr><tr><td>2.22.74</td><td>01/13/2026</td><td>RUN-34858</td><td>Fixed a security vulnerability related to CVE-2024-25621 with severity HIGH.</td></tr><tr><td>2.22.74</td><td>01/13/2026</td><td>RUN-35089</td><td>Fixed a security vulnerability related to CVE-2025-64756 with severity HIGH.</td></tr><tr><td>2.22.74</td><td>01/13/2026</td><td>RUN-35189</td><td>Fixed an issue where the <code>--working-dir</code> parameter was ignored for Knative-based inference workloads, causing containers to start in <code>/</code> instead of the specified directory.</td></tr><tr><td>2.22.74</td><td>01/13/2026</td><td>RUN-35290</td><td>Fixed an issue where copying a workload that included node affinity settings caused the re-submission to fail.</td></tr><tr><td>2.22.73</td><td>01/05/2026</td><td>RUN-34721</td><td>Fixed a security vulnerability related to CVE-2024-25621 with severity HIGH.</td></tr><tr><td>2.22.72</td><td>12/30/2025</td><td>RUN-34620</td><td>Fixed an issue where, in rare cases, sessions could disconnect due to token refresh handling.</td></tr><tr><td>2.22.71</td><td>12/25/2025</td><td>RUN-34678</td><td>Fixed a security vulnerability related to CVE-2025-58183 with severity HIGH.</td></tr><tr><td>2.22.71</td><td>12/25/2025</td><td>RUN-34932</td><td>Fixed a security vulnerability related to CVE-2025-58754 with severity HIGH.</td></tr><tr><td>2.22.69</td><td>12/22/2025</td><td>RUN-33516</td><td>Fixed an issue so each access rule created or deleted in a batch action is now audited in the events history.</td></tr><tr><td>2.22.69</td><td>12/22/2025</td><td>RUN-34613</td><td>Fixed an issue where the Project GET API returned missing limit fields instead of an explicit unlimited value when CPU quotas were enabled.</td></tr><tr><td>2.22.69</td><td>12/22/2025</td><td>RUN-34680</td><td>Fixed a security vulnerability related to CVE-2025-58183 with severity HIGH.</td></tr><tr><td>2.22.69</td><td>12/22/2025</td><td>RUN-34712</td><td>Fixed a security vulnerability related to CVE-2025-61729 with severity HIGH.</td></tr><tr><td>2.22.67</td><td>12/03/2025</td><td>RUN-31856</td><td>Fixed a security vulnerability related to CVE-2025-47907 with severity HIGH.</td></tr><tr><td>2.22.67</td><td>12/03/2025</td><td>RUN-33279</td><td>Fixed an issue with refresh-token handling in legacy Grafana dashboards that caused unexpected session logouts.</td></tr><tr><td>2.22.67</td><td>12/03/2025</td><td>RUN-33780</td><td>Fixed an issue where apps with the “Viewer” role could not access node metrics, even when they had read permissions at the cluster scope.</td></tr><tr><td>2.22.66</td><td>11/25/2025</td><td>RUN-33613</td><td>Fixed missing validations for CPU resources when the CPU quota feature flag was disabled, which caused project and department updates to skip required CPU checks.</td></tr><tr><td>2.22.66</td><td>11/25/2025</td><td>RUN-33956</td><td>Fixed an issue where workloads using an environment with multiple NodePorts could receive randomly allocated NodePort values.</td></tr><tr><td>2.22.66</td><td>11/25/2025</td><td>RUN-33862</td><td>Fixed an issue where the workloads service could enter a CrashLoopBackOff during upgrade.</td></tr><tr><td>2.22.65</td><td>11/20/2025</td><td>RUN-33947</td><td>Fixed an issue where SMTP configurations using the “none” option still sent empty username/password fields. Added the <code>auth_none</code> type to ensure no credentials are sent for passwordless SMTP servers.</td></tr><tr><td>2.22.64</td><td>10/29/2025</td><td>RUN-33388</td><td>Fixed an issue where dependency checks did not run properly for clusters installed with a remote control plane.</td></tr><tr><td>2.22.64</td><td>10/29/2025</td><td>RUN-33127</td><td>Fixed an issue where workload submission in the CLI failed when commands contained special characters.</td></tr><tr><td>2.22.64</td><td>10/29/2025</td><td>RUN-33144</td><td>Fixed a security vulnerability related to CVE-2025-62156 with severity HIGH.</td></tr><tr><td>2.22.63</td><td>10/27/2025</td><td>RUN-32968</td><td>Fixed an issue where users without permission to create data source assets were blocked from adding one-time data sources during workload submission.</td></tr><tr><td>2.22.63</td><td>10/27/2025</td><td>RUN-33006</td><td>Fixed an issue in the CLI installer where the PATH was not configured for all shells. The installer now correctly configures PATH for both zsh and bash.</td></tr><tr><td>2.22.62</td><td>10/23/2025</td><td>RUN-33235</td><td>Fixed a security vulnerability in the Valkey dependency.</td></tr><tr><td>2.22.61</td><td>10/22/2025</td><td>RUN-32989</td><td>Fixed an issue where the NVIDIA Run:ai operator experienced unusually high CPU utilization after upgrading to version 2.22.49.</td></tr><tr><td>2.22.60</td><td>10/22/2025</td><td>RUN-33053</td><td>Fixed an issue that caused conflicts with additional built-in Prometheus Operator deployments in OpenShift.</td></tr><tr><td>2.22.59</td><td>10/19/2025</td><td>RUN-32548</td><td>Fixed an issue where, in certain edge cases, removing an inference workload without deleting its revision caused the cluster to panic during revision sync.</td></tr><tr><td>2.22.59</td><td>10/19/2025</td><td>RUN-33044</td><td>Fixed an issue where the workload controller could delete all running workloads when <code>init-ca</code> generated a new certificate (every 30 days).</td></tr><tr><td>2.22.59</td><td>10/19/2025</td><td>RUN-31803</td><td>Fixed an issue where the Quota management dashboard occasionally displayed incorrect GPU quota values.</td></tr><tr><td>2.22.58</td><td>10/16/2025</td><td>RUN-32707</td><td>Fixed an issue where users running Red Hat OpenShift Serverless experienced “Down” status alerts in OpenShift monitoring due to NVIDIA Run:ai Knative ServiceMonitors.</td></tr><tr><td>2.22.58</td><td>10/16/2025</td><td>RUN-32572</td><td>Fixed an issue where the <code>RunaiAgentPullRateLow</code> and <code>RunaiAgentClusterInfoPushRateLow</code> Prometheus alerts were firing incorrectly without cause.</td></tr><tr><td>2.22.58</td><td>10/16/2025</td><td>RUN-32899</td><td>Fixed an issue where idle GPU timeout rules were incorrectly applied to preemptible workspaces.</td></tr><tr><td>2.22.58</td><td>10/16/2025</td><td>RUN-32986</td><td>Fixed an issue where PVCs appeared with the status “Issues found” after upgrading to version 2.22.</td></tr><tr><td>2.22.58</td><td>10/16/2025</td><td>RUN-33147</td><td>Fixed an issue where users with expired refresh tokens (after 24 hours) could not log in, as the token endpoint returned a 400 error.</td></tr><tr><td>2.22.57</td><td>10/16/2025</td><td>RUN-32073</td><td>Fixed an issue where the Node pool modal displayed only the first 50 nodes instead of the full node list.</td></tr><tr><td>2.22.57</td><td>10/16/2025</td><td>RUN-33039</td><td>Fixed an issue where setting <code>uid</code> or <code>gid</code> to <code>0</code> during environment creation was not allowed.</td></tr><tr><td>2.22.55</td><td>10/09/2025</td><td>RUN-32877</td><td>Fixed an issue where the <code>defaults.servingConfiguration.initializationTimeoutSeconds</code> policy did not apply correctly, causing default values to not appear as expected in the UI.</td></tr><tr><td>2.22.55</td><td>10/09/2025</td><td>RUN-32730</td><td>Fixed an issue where incorrect average GPU utilization per project and workload type was displayed in the Projects view charts and tables.</td></tr><tr><td>2.22.53</td><td>09/30/2025</td><td>RUN-32876</td><td>Fixed an issue where running a NIM inference workload on a fractional GPU prevented the Triton server from starting, causing inference endpoint requests to fail.</td></tr><tr><td>2.22.53</td><td>09/30/2025</td><td>RUN-32605</td><td>Fixed a security vulnerability related to CVE-2025-58754 with severity HIGH.</td></tr><tr><td>2.22.53</td><td>09/30/2025</td><td>RUN-32146</td><td>Fixed a security vulnerability related to CVE-2025-5914 with severity HIGH.</td></tr><tr><td>2.22.53</td><td>09/30/2025</td><td>RUN-31993</td><td>Fixed a security vulnerability related to CVE-2025-22868 with severity HIGH.</td></tr><tr><td>2.22.51</td><td>09/21/2025</td><td>RUN-31422</td><td>Fixed an issue where updating project resources created through the deprecated Projects API did not work correctly.</td></tr><tr><td>2.22.51</td><td>09/21/2025</td><td>RUN-32159</td><td>Fixed an issue where the <code>updatedBy</code> field of a policy did not show the latest user who updated it.</td></tr><tr><td>2.22.51</td><td>09/21/2025</td><td>RUN-32551</td><td>Fixed an issue where inference workloads failed when using user credentials as an image pull secret.</td></tr><tr><td>2.22.51</td><td>09/21/2025</td><td>RUN-32554</td><td>Fixed a security vulnerability related to CVE-2025-22874 with severity HIGH.</td></tr><tr><td>2.22.51</td><td>09/21/2025</td><td>RUN-32601</td><td>Fixed an issue where external token exchange failed because the API was incompatible with <code>access_tokens</code>.</td></tr><tr><td>2.22.51</td><td>09/21/2025</td><td>RUN-32789</td><td>Fixed an issue in CLI v2 where the <code>--master-extended-resource</code> flag had no effect in MPI training workloads.</td></tr><tr><td>2.22.45</td><td>09/02/2025</td><td>RUN-32123</td><td>Fixed an issue where email notifications configured through User Settings were still sent after selecting and then immediately de-selecting all notification types.</td></tr><tr><td>2.22.43</td><td>08/31/2025</td><td>RUN-31961</td><td>Fixed a security vulnerability related to CVE-2025-7425 with severity HIGH</td></tr><tr><td>2.22.43</td><td>08/31/2025</td><td>RUN-31797</td><td>Fixed a security vulnerability related to CVE-2025-53547 with severity HIGH.</td></tr><tr><td>2.22.43</td><td>08/31/2025</td><td>RUN-31383</td><td>Fixed a security vulnerability related to CVE-2025-7783 with severity HIGH.</td></tr><tr><td>2.22.42</td><td>08/28/2025</td><td>RUN-31423</td><td>Fixed an issue where schedulers for different node pools were not scheduling jobs, causing workloads to remain Pending.</td></tr><tr><td>2.22.41</td><td>08/27/2025</td><td>RUN-32085</td><td>Fixed an issue where custom inference workloads could not be created after enabling flexible workload submission.</td></tr><tr><td>2.22.37</td><td>08/20/2025</td><td>RUN-31304</td><td>Fixed a security vulnerability related to CVE-2025-22868 with severity HIGH.</td></tr><tr><td>2.22.37</td><td>08/20/2025</td><td>RUN-31652</td><td>Fixed a security vulnerability related to CVE-2025-7425 with severity HIGH.</td></tr><tr><td>2.22.37</td><td>08/20/2025</td><td>RUN-31852</td><td>Fixed a security vulnerability in <code>stdlib</code> with CVE-2025-47907 with severity HIGH.</td></tr><tr><td>2.22.35</td><td>08/18/2025</td><td>RUN-31965</td><td>Fixed a security vulnerability related to CVE-2025-22868 with severity HIGH.</td></tr><tr><td>2.22.35</td><td>08/18/2025</td><td>RUN-31571</td><td>Fixed a security vulnerability related to CVE-2025-6965 with severity HIGH.</td></tr><tr><td>2.22.34</td><td>08/17/2025</td><td>RUN-31792</td><td>Fixed a security vulnerability related to CVE-2025-7425 with severity HIGH.</td></tr><tr><td>2.22.34</td><td>08/17/2025</td><td>RUN-31860</td><td>Fixed a security vulnerability related to CVE-2025-47907 with severity HIGH.</td></tr><tr><td>2.22.33</td><td>08/14/2025</td><td>RUN-31306</td><td>Fixed a security vulnerability related to CVE-2025-22868 with severity HIGH.</td></tr><tr><td>2.22.33</td><td>08/14/2025</td><td>RUN-31855</td><td>Fixed a security vulnerability related to CVE-2025-47907 with severity HIGH.</td></tr><tr><td>2.22.31</td><td>08/14/2025</td><td>RUN-31687</td><td>Fixed an issue where the workload flexible submission form did not load the correct default node pools for a project.</td></tr><tr><td>2.22.27</td><td>08/04/2025</td><td>RUN-28394</td><td>Fixed an issue where the "Get Role by ID" API returned an "insufficient permissions" error for system administrator.</td></tr><tr><td>2.22.27</td><td>08/04/2025</td><td>RUN-31008</td><td>Fixed a security vulnerability related to CVE-2025-53547 with severity HIGH.</td></tr><tr><td>2.22.27</td><td>08/04/2025</td><td>RUN-31051</td><td>Fixed a security vulnerability related to CVE-2025-49794 with severity HIGH.</td></tr><tr><td>2.22.26</td><td>08/04/2025</td><td>RUN-29610</td><td>Fixed a security vulnerability related to CVE-2025-30204 with severity HIGH.</td></tr><tr><td>2.22.26</td><td>08/04/2025</td><td>RUN-31265</td><td>Fixed a security vulnerability related to CVE-2025-30749 with severity HIGH.</td></tr><tr><td>2.22.23</td><td>07/30/2025</td><td>RUN-31275</td><td>Fixed an issue where some returned objects in List Workload Types API had an empty "id" field</td></tr><tr><td>2.22.22</td><td>07/30/2025</td><td>RUN-29828</td><td>Fixed an issue where the completion time date formatting in the Workload grid was inconsistent. Also resolved a bug where exported CSV files shifted date values to the next cell.</td></tr><tr><td>2.22.22</td><td>07/30/2025</td><td>RUN-31024</td><td>Fixed an issue where inconsistent deletion behavior occurred for admin access rules between the Users and Access rules grid. The system now prevents deletion of the last remaining system admin rule to ensure at least one system admin remains.</td></tr><tr><td>2.22.22</td><td>07/30/2025</td><td>RUN-31039</td><td>Fixed a base image security vulnerability in <code>libxml2</code> related to CVE-2025-49796 with severity HIGH.</td></tr><tr><td>2.22.22</td><td>07/30/2025</td><td>RUN-31524</td><td>Fixed an issue where the CLI would panic when submitting a workload with non-compliant policy rules defined for the tenant</td></tr><tr><td>2.22.22</td><td>07/30/2025</td><td>RUN-31263</td><td>Fixed an issue where setting defaults for servingPort fields failed and incorrectly required the container port default as well.</td></tr><tr><td>2.22.22</td><td>07/30/2025</td><td>RUN-31305</td><td>Fixed a security vulnerability in <code>golang.org/x/oauth2</code> related to CVE-2025-22868 with severity HIGH.</td></tr><tr><td>2.22.22</td><td>07/30/2025</td><td>RUN-31380</td><td>Fixed an issue where the SAML metadata XML redirect URL was invalid.</td></tr><tr><td>2.22.20</td><td>07/20/2025</td><td>RUN-29092</td><td>Fixed an issue where project quota could not be changed due to scheduling rules being set to 0 instead of null.</td></tr><tr><td>2.22.17</td><td>07/15/2025</td><td>RUN-31129</td><td>Fixed an issue where the Inference Policy view option was missing from the Project and Department grid.</td></tr><tr><td>2.22.16</td><td>07/15/2025</td><td>RUN-31066</td><td>Fixed an issue where the validation for the number of workers in a policy was not applied correctly.</td></tr><tr><td>2.22.16</td><td>07/15/2025</td><td>RUN-37040</td><td>Fixed an issue where negative values were allowed for GPU resource optimization swap size in node pool settings</td></tr></tbody></table>
