A maintenance release with a security fix for an external authorization bypass and dependency updates for CVE fixes. It also updates the tested Kubernetes range to 1.32 through 1.34, Go to 1.25.12, and Envoy to v1.38.3.
Action needed (1)
securityDependency updates for CVE fixes
Dependencies were updated to fix CVEs. The updates ship in Contour v1.33.6.
Check if affected (1)
securityExternal authorization bypass with disabled
authPolicyApplies if
authPolicyis not configured.The fix for GHSA-cf57-xf33-fg5h addresses an external authorization bypass when
authPolicyis disabled. It ships in Contour v1.33.6.