RATATOSKRATATOSK
Sign in

Contour

v1.33.6Networking & Messaging
Aug 12, 2026

ACTION 1CHECK 1OTHER 3

Contour v1.33.6 is a maintenance release with a security fix for external authorization and dependency updates addressing CVEs. It also updates dependency versions and the tested Kubernetes version range.

Action needed (1)

  • securityDependency updates for CVE fixes

    Contour v1.33.6 updates dependencies to fix CVEs.

Check if affected (1)

  • securityGHSA-cf57-xf33-fg5h external authorization bypass

    Applies if you use virtualhost authPolicy settings.

    GHSA-cf57-xf33-fg5h fixes an external authorization bypass when virtualhost authPolicy is disabled. The fix ships in Contour v1.33.6.

All 3 other recorded changesvalue changes 2 · constraints 1

value changes (2)

  • Bumps Go to [1.25.12](https://go.dev/doc/devel/release#go1.25.minor).
  • - Updates Envoy to v1.38.3.

constraints (1)

  • Contour v1.33.6 is tested against Kubernetes 1.32 through 1.34.
Add Contour to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack