Contour v1.33.6 (Helm chart 0.7.0) ships Envoy v1.38.3.
Envoy v1.38.4 was released on August 26, 2026 and contains 13 security
fixes plus bug fixes. Notable CVEs:
- CVE-2026-73553 — RBAC authz bypass via path parameters
- CVE-2026-73548 — HTTP upgrade request smuggling (upstream connection poisoning)
- CVE-2026-73511 — URL normalization bypass (path parameter stripping)
- CVE-2026-73551 — URL normalization bypass via
/.; / /..; segments
- CVE-2026-73512 — HTTP/3 use-after-free
- CVE-2026-73513 — HTTP/2 abnormal termination
- CVE-2026-50572 — ext_authz use-after-free
- CVE-2026-73547 — ext_authz crash on CONNECT requests
- CVE-2026-73550 — HTTP/2 Host header size limit bypass
- CVE-2026-73552 — Regex charset bypass (UTF-8 vs Latin1)
- CVE-2026-48521 — HTTP/3 crash with ALPN
- CVE-2026-73546 — Admin HTML injection
- CVE-2026-73549 — QUIC crash on scoped IPv6
Full release notes: https://github.com/envoyproxy/envoy/releases/tag/v1.38.4
Would it be possible to get a Contour patch release (v1.33.7) with the
Envoy bump? Several of these CVEs affect authorization and URL
normalization, which are security-critical for ingress controllers.
Contour v1.33.6 (Helm chart 0.7.0) ships Envoy v1.38.3.
Envoy v1.38.4 was released on August 26, 2026 and contains 13 security
fixes plus bug fixes. Notable CVEs:
/.;//..;segmentsFull release notes: https://github.com/envoyproxy/envoy/releases/tag/v1.38.4
Would it be possible to get a Contour patch release (v1.33.7) with the
Envoy bump? Several of these CVEs affect authorization and URL
normalization, which are security-critical for ingress controllers.