Contour v1.32.5 fixes a Lua code injection vulnerability and upgrades Envoy to v1.34.14. The release also includes an informational Kubernetes compatibility update.
Action needed (1)
securityhighCVE-2026-41246 Lua code injection vulnerability fixed
This release fixes CVE-2026-41246 and GHSA-x4mj-7f9g-29h4, a Lua code injection vulnerability affecting
cookieRewritePolicies[]..pathRewrite. value