Skip to content

Bump Envoy to v1.38.4 (13 security fixes) #7712

Description

@shoerl1987

Contour v1.33.6 (Helm chart 0.7.0) ships Envoy v1.38.3.

Envoy v1.38.4 was released on August 26, 2026 and contains 13 security
fixes plus bug fixes. Notable CVEs:

  • CVE-2026-73553 — RBAC authz bypass via path parameters
  • CVE-2026-73548 — HTTP upgrade request smuggling (upstream connection poisoning)
  • CVE-2026-73511 — URL normalization bypass (path parameter stripping)
  • CVE-2026-73551 — URL normalization bypass via /.; / /..; segments
  • CVE-2026-73512 — HTTP/3 use-after-free
  • CVE-2026-73513 — HTTP/2 abnormal termination
  • CVE-2026-50572 — ext_authz use-after-free
  • CVE-2026-73547 — ext_authz crash on CONNECT requests
  • CVE-2026-73550 — HTTP/2 Host header size limit bypass
  • CVE-2026-73552 — Regex charset bypass (UTF-8 vs Latin1)
  • CVE-2026-48521 — HTTP/3 crash with ALPN
  • CVE-2026-73546 — Admin HTML injection
  • CVE-2026-73549 — QUIC crash on scoped IPv6

Full release notes: https://github.com/envoyproxy/envoy/releases/tag/v1.38.4

Would it be possible to get a Contour patch release (v1.33.7) with the
Envoy bump? Several of these CVEs affect authorization and URL
normalization, which are security-critical for ingress controllers.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions