RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Apr 2026Clear ×Project: ContourClear ×
Contourv1.33.4Networking & MessagingApr 20, 2026

A release with a fix for Lua code injection, a required Envoy version change, and an Envoy dependency update. It is tested against Kubernetes 1.32 through 1.34.

Check if affected (2)

  • securityhighCVE-2026-41246 fix for cookieRewritePolicies[].pathRewrite.value

    Applies if you use HTTPProxy resources.

    CVE-2026-41246 and GHSA-x4mj-7f9g-29h4 address arbitrary code execution in the Envoy proxy. An attacker with RBAC permissions to create or modify HTTPProxy resources could exploit a malicious cookieRewritePolicies[].pathRewrite.value.

  • breakingEnvoy 1.35.0 minimum version

    Applies if you depend on Envoy.

    This release requires Envoy 1.35.0 or later.

Source
Contourv1.32.5Networking & MessagingApr 20, 2026

Contour v1.32.5 fixes a Lua code injection vulnerability and upgrades Envoy to v1.34.14. The release also includes an informational Kubernetes compatibility update.

Action needed (1)

  • securityhighCVE-2026-41246 Lua code injection vulnerability fixed

    This release fixes CVE-2026-41246 and GHSA-x4mj-7f9g-29h4, a Lua code injection vulnerability affecting cookieRewritePolicies[].pathRewrite.value.

Source
Contourv1.31.6Networking & MessagingApr 20, 2026

This release fixes a Lua code injection vulnerability in Contour's Cookie Rewriting feature and updates Envoy to v1.34.14. It is tested against Kubernetes 1.30 through 1.32.

Check if affected (1)

  • securityhighLua code injection fix for CVE-2026-41246

    Applies if you configure cookieRewritePolicies[].pathRewrite.value.

    The release fixes a Lua code injection vulnerability in Contour's Cookie Rewriting feature, tracked as CVE-2026-41246 and GHSA-x4mj-7f9g-29h4. The affected configuration field is cookieRewritePolicies[].pathRewrite.value.

Source
Browse by month