RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: ContourClear ×
Contourv1.33.6Networking & MessagingAug 12, 2026

A maintenance release with a security fix for an external authorization bypass and dependency updates for CVE fixes. It also updates the tested Kubernetes range to 1.32 through 1.34, Go to 1.25.12, and Envoy to v1.38.3.

Action needed (1)

  • securityDependency updates for CVE fixes

    Dependencies were updated to fix CVEs. The updates ship in Contour v1.33.6.

Check if affected (1)

  • securityExternal authorization bypass with disabled authPolicy

    Applies if authPolicy is not configured.

    The fix for GHSA-cf57-xf33-fg5h addresses an external authorization bypass when authPolicy is disabled. It ships in Contour v1.33.6.

Source
Contourv1.33.5Networking & MessagingMay 28, 2026

A maintenance release with a security fix for invalid HTTPProxy configurations and an update to golang.org/x/net. It also updates the Go toolchain to 1.25.10 and is tested against Kubernetes 1.32 through 1.34.

Action needed (1)

  • securitycriticalgolang.org/x/net updated to v0.55.0, CVE-2026-39821

    Contour v1.33.5 updates golang.org/x/net to v0.55.0. The change addresses CVE-2026-39821.

Check if affected (1)

  • securitymediumInvalid HTTPProxy configuration rejected, GHSA-g3xr-5w5j-w4q4

    Applies if you configure HTTPProxy with a fallback certificate and enable JWT verification.

    Contour rejects an invalid HTTPProxy configuration in which a fallback certificate is configured with JWT verification. This prevents requests without TLS SNI or with unrecognized SNI from bypassing JWT verification. Advisory: GHSA-g3xr-5w5j-w4q4.

Source
Contourv1.33.4Networking & MessagingApr 20, 2026

A release with a fix for Lua code injection, a required Envoy version change, and an Envoy dependency update. It is tested against Kubernetes 1.32 through 1.34.

Check if affected (2)

  • securityhighCVE-2026-41246 fix for cookieRewritePolicies[].pathRewrite.value

    Applies if you use HTTPProxy resources.

    CVE-2026-41246 and GHSA-x4mj-7f9g-29h4 address arbitrary code execution in the Envoy proxy. An attacker with RBAC permissions to create or modify HTTPProxy resources could exploit a malicious cookieRewritePolicies[].pathRewrite.value.

  • breakingEnvoy 1.35.0 minimum version

    Applies if you depend on Envoy.

    This release requires Envoy 1.35.0 or later.

Source
Contourv1.32.5Networking & MessagingApr 20, 2026

Contour v1.32.5 fixes a Lua code injection vulnerability and upgrades Envoy to v1.34.14. The release also includes an informational Kubernetes compatibility update.

Action needed (1)

  • securityhighCVE-2026-41246 Lua code injection vulnerability fixed

    This release fixes CVE-2026-41246 and GHSA-x4mj-7f9g-29h4, a Lua code injection vulnerability affecting cookieRewritePolicies[].pathRewrite.value.

Source
Contourv1.31.6Networking & MessagingApr 20, 2026

This release fixes a Lua code injection vulnerability in Contour's Cookie Rewriting feature and updates Envoy to v1.34.14. It is tested against Kubernetes 1.30 through 1.32.

Check if affected (1)

  • securityhighLua code injection fix for CVE-2026-41246

    Applies if you configure cookieRewritePolicies[].pathRewrite.value.

    The release fixes a Lua code injection vulnerability in Contour's Cookie Rewriting feature, tracked as CVE-2026-41246 and GHSA-x4mj-7f9g-29h4. The affected configuration field is cookieRewritePolicies[].pathRewrite.value.

Source
Contourv1.33.3Networking & MessagingMar 23, 2026

A maintenance release with security-related dependency updates and removal of the hostPort setting from example manifests. It also documents compatibility testing with Kubernetes 1.32 through 1.34.

Action needed (2)

  • securitycriticalgoogle.golang.org/grpc v1.79.3 update

    google.golang.org/grpc is updated to v1.79.3, which addresses CVE-2026-33186 and GHSA-p77j-4mvh-x3m3. Contour is not affected by this advisory.

  • securityEnvoy v1.35.9 update

    The Envoy dependency is updated to v1.35.9 to address security vulnerabilities.

Check if affected (1)

  • breakingRemoval of hostPort: 8002 from example manifests

    Applies if you use hostPort in example manifests.

    The hostPort: 8002 Envoy metrics setting is removed from example manifests.

Source
Contourv1.32.4Networking & MessagingMar 23, 2026

A maintenance release with updated Envoy and gRPC dependencies, plus a change to the example manifests. It is tested against Kubernetes 1.31 through 1.33.

Action needed (2)

  • securitycriticalgoogle.golang.org/grpc updated to v1.79.3

    google.golang.org/grpc is updated to v1.79.3, which addresses CVE-2026-33186 and GHSA-p77j-4mvh-x3m3. Contour is not affected.

  • securityEnvoy updated to v1.34.13

    Envoy is updated to v1.34.13 to address security vulnerabilities and improve stability.

Check if affected (1)

  • breakinghostPort: 8002 removed from example manifests

    Applies if hostPort: 8002 is configured in example manifests.

    The Envoy metric configuration hostPort: 8002 is removed from example manifests.

Source
Contourv1.31.5Networking & MessagingMar 23, 2026

A maintenance release contains dependency security updates and an example-manifest cleanup. It also documents testing against Kubernetes 1.30 through 1.32.

Action needed (2)

  • securitycriticalgoogle.golang.org/grpc updated to v1.79.3 for CVE-2026-33186

    The release updates google.golang.org/grpc to v1.79.3, which addresses CVE-2026-33186 and GHSA-p77j-4mvh-x3m3. Contour is not affected.

  • securityEnvoy updated to v1.34.13

    The release bumps Envoy to v1.34.13.

Check if affected (1)

  • breakingEnvoy metrics hostPort: 8002 removed from example manifests

    Applies if example manifests use hostPort: 8002.

    Envoy metrics hostPort: 8002 are removed from example manifests.

Source
Browse by month