RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: ContourClear ×
Contourv1.33.6Networking & MessagingAug 12, 2026

A maintenance release with a security fix for an external authorization bypass and dependency updates for CVE fixes. It also updates the tested Kubernetes range to 1.32 through 1.34, Go to 1.25.12, and Envoy to v1.38.3.

Action needed (1)

  • securityDependency updates for CVE fixes

    Dependencies were updated to fix CVEs. The updates ship in Contour v1.33.6.

Check if affected (1)

  • securityExternal authorization bypass with disabled authPolicy

    Applies if authPolicy is not configured.

    The fix for GHSA-cf57-xf33-fg5h addresses an external authorization bypass when authPolicy is disabled. It ships in Contour v1.33.6.

Source
Contourv1.33.5Networking & MessagingMay 28, 2026

A maintenance release with a security fix for invalid HTTPProxy configurations and an update to golang.org/x/net. It also updates the Go toolchain to 1.25.10 and is tested against Kubernetes 1.32 through 1.34.

Action needed (1)

  • securitycriticalgolang.org/x/net updated to v0.55.0, CVE-2026-39821

    Contour v1.33.5 updates golang.org/x/net to v0.55.0. The change addresses CVE-2026-39821.

Check if affected (1)

  • securitymediumInvalid HTTPProxy configuration rejected, GHSA-g3xr-5w5j-w4q4

    Applies if you configure HTTPProxy with a fallback certificate and enable JWT verification.

    Contour rejects an invalid HTTPProxy configuration in which a fallback certificate is configured with JWT verification. This prevents requests without TLS SNI or with unrecognized SNI from bypassing JWT verification. Advisory: GHSA-g3xr-5w5j-w4q4.

Source
Contourv1.33.4Networking & MessagingApr 20, 2026

A release with a fix for Lua code injection, a required Envoy version change, and an Envoy dependency update. It is tested against Kubernetes 1.32 through 1.34.

Check if affected (2)

  • securityhighCVE-2026-41246 fix for cookieRewritePolicies[].pathRewrite.value

    Applies if you use HTTPProxy resources.

    CVE-2026-41246 and GHSA-x4mj-7f9g-29h4 address arbitrary code execution in the Envoy proxy. An attacker with RBAC permissions to create or modify HTTPProxy resources could exploit a malicious cookieRewritePolicies[].pathRewrite.value.

  • breakingEnvoy 1.35.0 minimum version

    Applies if you depend on Envoy.

    This release requires Envoy 1.35.0 or later.

Source
Contourv1.31.6Networking & MessagingApr 20, 2026

This release fixes a Lua code injection vulnerability in Contour's Cookie Rewriting feature and updates Envoy to v1.34.14. It is tested against Kubernetes 1.30 through 1.32.

Check if affected (1)

  • securityhighLua code injection fix for CVE-2026-41246

    Applies if you configure cookieRewritePolicies[].pathRewrite.value.

    The release fixes a Lua code injection vulnerability in Contour's Cookie Rewriting feature, tracked as CVE-2026-41246 and GHSA-x4mj-7f9g-29h4. The affected configuration field is cookieRewritePolicies[].pathRewrite.value.

Source
Browse by month