A release with a fix for Lua code injection, a required Envoy version change, and an Envoy dependency update. It is tested against Kubernetes 1.32 through 1.34.
Check if affected (2)
securityhighCVE-2026-41246 fix for
cookieRewritePolicies[].pathRewrite. value Applies if you use
HTTPProxyresources.CVE-2026-41246 and GHSA-x4mj-7f9g-29h4 address arbitrary code execution in the Envoy proxy. An attacker with RBAC permissions to create or modify
HTTPProxyresources could exploit a maliciouscookieRewritePolicies[]..pathRewrite. value breaking
Envoy1.35.0 minimum versionApplies if you depend on
Envoy.This release requires
Envoy1.35.0 or later.