Contour
v1.33.6Networking & MessagingAug 12, 2026
Contour v1.33.6 is a maintenance release with a security fix for external authorization and dependency updates addressing CVEs. It also updates dependency versions and the tested Kubernetes version range.
Action needed (1)
securityDependency updates for CVE fixes
Contour v1.33.6 updates dependencies to fix CVEs.
Check if affected (1)
securityGHSA-cf57-xf33-fg5h external authorization bypass
Applies if you use virtualhost
authPolicysettings.GHSA-cf57-xf33-fg5h fixes an external authorization bypass when virtualhost
authPolicyis disabled. The fix ships in Contour v1.33.6.
All 3 other recorded changesvalue changes 2 · constraints 1
value changes (2)
- Bumps Go to [1.25.12](https://go.dev/doc/devel/release#go1.25.minor).
- - Updates Envoy to v1.38.3.
constraints (1)
- Contour v1.33.6 is tested against Kubernetes 1.32 through 1.34.
Add Contour to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.