Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
v1.9.0
v1.9.1
42 changes: 42 additions & 0 deletions release-notes/v1.9.1.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
date: August 28, 2026

# Changes that are expected to cause an incompatibility with previous versions, such as deletions or modifications to existing APIs.
breaking changes: |
Reverted the `0s` initial timeout for SDS and RDS because it could cause Envoy to wait indefinitely and block subsequent xDS updates. Both now use the default 15-second initial timeout.
The `watchable_subscribe_duration_seconds` histogram bucket boundaries changed from `{0.001, 0.01, 0.1, 1, 5, 10}` to `{0.005, 0.025, 0.1, 0.25, 0.5, 1, 2, 4, 8, 15, 30, 60, 120}` to improve latency resolution. The metric name and its `_sum`/`_count` series are unchanged, but `_bucket` series with `le="0.001"`, `le="0.01"`, `le="5"`, and `le="10"` are no longer emitted; `le="0.1"` and `le="1"` remain available. Update any dashboard, alert, or recording rule that references the removed boundaries directly. Queries that aggregate dynamically by `le`, such as `histogram_quantile()`, do not require changes.
HTTP is no longer supported as an OIDC issuer URL scheme.
OCI Wasm image pulls now require the registry to serve HTTPS. The implicit fallback to plain HTTP has been removed, so a Wasm extension backed by a plain HTTP registry will fail to load unless that registry is explicitly configured as insecure.

# Updates addressing vulnerabilities, security flaws, or compliance requirements.
security updates: |
Enabled AES-256-GCM encryption for OAuth2/OIDC session cookies and disabled the legacy AES-256-CBC decryption path in the Envoy proxy bootstrap, addressing the padding oracle in CVE-2026-47775. Existing OIDC sessions were encrypted with AES-256-CBC and are no longer accepted, so users with an active session are redirected to re-authenticate once after upgrading. This is set in the default bootstrap, so an `EnvoyProxy` using `spec.bootstrap` with type `Replace` (the default when no type is given) does not receive it; OIDC users with a replacement bootstrap must add `envoy.reloadable_features.oauth2_use_gcm_encryption: true` and `envoy.reloadable_features.oauth2_legacy_cbc_decrypt_compat: false` to a `layered_runtime` static layer themselves.
Added validation for the OIDC issuer URL configured in SecurityPolicy.
Fixed a nil pointer dereference in SecurityPolicy translation for TCPRoutes: a listener with no corresponding xDS IR entry (for example, a Gateway listener marked `Conflicted` for sharing a port with another listener) could panic the control plane during translation, silently dropping that reconcile's IR and status publication.
Fixed a confused-deputy/PSA-escape issue (GHSA-w42f-28h3-998w) where a tenant-supplied `KubernetesContainerSpec.SecurityContext` on an `EnvoyProxy` replaced Envoy Gateway's hardened default `SecurityContext` outright instead of merging on top of it, allowing a tenant whose `EnvoyProxy` is materialized in the shared controller namespace to drop restrictions (e.g. run privileged or as root) that the controller namespace's Pod Security Admission would otherwise enforce.
Fixed a control-plane availability issue in EnvoyExtensionPolicy Wasm OCI permission handling.
Fixed OCI Wasm image pulls silently downgrading to plain HTTP when the registry rejected the HTTPS request, which allowed an on-path attacker to serve arbitrary Wasm code to the Envoy proxies. Plain HTTP is now used only for registries that are explicitly configured as insecure.

# New features or capabilities added in this release.
new features: |

bug fixes: |
Fixed OIDC flow-state cookies accumulating in the browser and overflowing the request header size limit. Envoy mints a nonce (CSRF) and a PKCE code verifier cookie for every authorization flow it starts, but only deletes the pair belonging to the flow that completes the callback, so flows that are abandoned - parallel requests from a logged out browser, a user navigating away from the provider's login page - leave their cookies behind until they expire. Envoy Gateway now scopes both cookies to the OIDC redirect path, the only path where Envoy needs their value, so any orphans are no longer sent on every request. Note this bounds the damage rather than eliminating it: orphans are still sent to the callback endpoint itself until they expire, and logout can no longer purge them early because the browser no longer sends them to the signout path, so also consider lowering `csrfTokenTTL`. The PKCE code verifier cookie is also now named `CodeVerifier-<suffix>`, carrying the same per-policy suffix as the other OAuth2 cookies instead of Envoy's shared default, so SecurityPolicies on the same cookie domain no longer delete each other's in-flight flow cookies on logout. On upgrade, a browser already holding flow cookies keeps them at the old `path=/`, since the new deletion headers are scoped to the redirect path. They expire on the lifetime they were originally issued with - 10 minutes by default, and unaffected by any `csrfTokenTTL` you configure during the upgrade. The old code verifier cookie name is also no longer read, so a login that was in progress across the rollout may need to be retried once.
Fixed HTTPRoute (and other xRoute) acceptance not being re-evaluated when a namespace's labels changed to newly match, or stop matching, a Gateway listener's `allowedRoutes.namespaces.from: Selector`, requiring a controller restart to pick up the change. Envoy Gateway now watches Namespace label updates and re-reconciles affected Gateways automatically.
Fixed HTTPRoutes attached to a listener that won a hostname conflict being rejected with `NoMatchingListenerHostname` and omitted from xDS by excluding conflict-losing listeners from route hostname filtering.
Fixed the controller crash-looping when an extension manager's `backendResources` references a CRD that is not installed in the cluster. The CRD existence is now checked once at controller startup and cached in a field on the reconciler, following the same pattern already used for `ServiceImport`, `Backend`, and other optional CRDs. When the CRD is absent, both the watch and the reconcile list path are skipped; all other errors from the list call are returned so the reconcile is retried instead of publishing an incomplete resource snapshot.
The global rate limit cluster is now built from the in-cluster `envoy-ratelimit` Service/EndpointSlices using EDS instead of resolving a static DNS hostname, so requests keep hitting rate limit service replicas correctly as they scale up or down. When the Service or its endpoints can't be discovered, Envoy Gateway falls back to the previous STRICT_DNS behavior.
Fixed the File and ALS access log sinks silently falling back to the default JSON fields when `telemetry.accessLog.settings[].format` sets `text` without `type`, which the API accepts.
Fixed a `BackendTrafficPolicy` setting a `ConsistentHash` load balancer having no effect when it targets a `UDPRoute`. The cluster was configured with Maglev, but no hash policy was set on the UDP proxy listener filter, so Envoy had no hash key to compute and fell back to picking an upstream host at random for every UDP session. The source IP hash policy is now configured on the UDP proxy. Only the `SourceIP` consistent hash type applies to UDP, since headers, cookies and query parameters do not exist in a UDP datagram.
Fixed controller panic when translating backend credential injection with an invalid header.
Fixed the Wasm image permission cache key omitting the CA certificate, which allowed a permission check result to be reused across different TLS trust configurations.

# Enhancements that improve performance.
performance improvements: |
Improved reconcile performance by listing the extension manager's `resources` and `backendResources` once per GatewayClass instead of once per Gateway.

# Deprecated features or APIs.
deprecations: |

# Other notable changes not covered by the above sections.
Other changes: |
Added per-phase tracing spans to the Gateway API and xDS translators, each recording the size of the input it processed, so that a slow translation can be attributed to a specific phase — listener processing, HTTP and gRPC route processing, the main policy types, EnvoyPatchPolicy JSON patches, extension server hooks, and xDS resource validation — instead of showing up as one opaque multi-second span.
44 changes: 44 additions & 0 deletions site/content/en/news/releases/notes/v1.9.1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
---
title: "v1.9.1"
publishdate: 2026-08-28
---

Date: August 28, 2026

## Breaking changes
- Reverted the `0s` initial timeout for SDS and RDS because it could cause Envoy to wait indefinitely and block subsequent xDS updates. Both now use the default 15-second initial timeout.
- The `watchable_subscribe_duration_seconds` histogram bucket boundaries changed from `{0.001, 0.01, 0.1, 1, 5, 10}` to `{0.005, 0.025, 0.1, 0.25, 0.5, 1, 2, 4, 8, 15, 30, 60, 120}` to improve latency resolution. The metric name and its `_sum`/`_count` series are unchanged, but `_bucket` series with `le="0.001"`, `le="0.01"`, `le="5"`, and `le="10"` are no longer emitted; `le="0.1"` and `le="1"` remain available. Update any dashboard, alert, or recording rule that references the removed boundaries directly. Queries that aggregate dynamically by `le`, such as `histogram_quantile()`, do not require changes.
- HTTP is no longer supported as an OIDC issuer URL scheme.
- OCI Wasm image pulls now require the registry to serve HTTPS. The implicit fallback to plain HTTP has been removed, so a Wasm extension backed by a plain HTTP registry will fail to load unless that registry is explicitly configured as insecure.

## Security updates
- Enabled AES-256-GCM encryption for OAuth2/OIDC session cookies and disabled the legacy AES-256-CBC decryption path in the Envoy proxy bootstrap, addressing the padding oracle in CVE-2026-47775. Existing OIDC sessions were encrypted with AES-256-CBC and are no longer accepted, so users with an active session are redirected to re-authenticate once after upgrading. This is set in the default bootstrap, so an `EnvoyProxy` using `spec.bootstrap` with type `Replace` (the default when no type is given) does not receive it; OIDC users with a replacement bootstrap must add `envoy.reloadable_features.oauth2_use_gcm_encryption: true` and `envoy.reloadable_features.oauth2_legacy_cbc_decrypt_compat: false` to a `layered_runtime` static layer themselves.
- Added validation for the OIDC issuer URL configured in SecurityPolicy.
- Fixed a nil pointer dereference in SecurityPolicy translation for TCPRoutes: a listener with no corresponding xDS IR entry (for example, a Gateway listener marked `Conflicted` for sharing a port with another listener) could panic the control plane during translation, silently dropping that reconcile's IR and status publication.
- Fixed a confused-deputy/PSA-escape issue (GHSA-w42f-28h3-998w) where a tenant-supplied `KubernetesContainerSpec.SecurityContext` on an `EnvoyProxy` replaced Envoy Gateway's hardened default `SecurityContext` outright instead of merging on top of it, allowing a tenant whose `EnvoyProxy` is materialized in the shared controller namespace to drop restrictions (e.g. run privileged or as root) that the controller namespace's Pod Security Admission would otherwise enforce.
- Fixed a control-plane availability issue in EnvoyExtensionPolicy Wasm OCI permission handling.
- Fixed OCI Wasm image pulls silently downgrading to plain HTTP when the registry rejected the HTTPS request, which allowed an on-path attacker to serve arbitrary Wasm code to the Envoy proxies. Plain HTTP is now used only for registries that are explicitly configured as insecure.

## New features
-

## Bug fixes
- Fixed OIDC flow-state cookies accumulating in the browser and overflowing the request header size limit. Envoy mints a nonce (CSRF) and a PKCE code verifier cookie for every authorization flow it starts, but only deletes the pair belonging to the flow that completes the callback, so flows that are abandoned - parallel requests from a logged out browser, a user navigating away from the provider's login page - leave their cookies behind until they expire. Envoy Gateway now scopes both cookies to the OIDC redirect path, the only path where Envoy needs their value, so any orphans are no longer sent on every request. Note this bounds the damage rather than eliminating it: orphans are still sent to the callback endpoint itself until they expire, and logout can no longer purge them early because the browser no longer sends them to the signout path, so also consider lowering `csrfTokenTTL`. The PKCE code verifier cookie is also now named `CodeVerifier-<suffix>`, carrying the same per-policy suffix as the other OAuth2 cookies instead of Envoy's shared default, so SecurityPolicies on the same cookie domain no longer delete each other's in-flight flow cookies on logout. On upgrade, a browser already holding flow cookies keeps them at the old `path=/`, since the new deletion headers are scoped to the redirect path. They expire on the lifetime they were originally issued with - 10 minutes by default, and unaffected by any `csrfTokenTTL` you configure during the upgrade. The old code verifier cookie name is also no longer read, so a login that was in progress across the rollout may need to be retried once.
- Fixed HTTPRoute (and other xRoute) acceptance not being re-evaluated when a namespace's labels changed to newly match, or stop matching, a Gateway listener's `allowedRoutes.namespaces.from: Selector`, requiring a controller restart to pick up the change. Envoy Gateway now watches Namespace label updates and re-reconciles affected Gateways automatically.
- Fixed HTTPRoutes attached to a listener that won a hostname conflict being rejected with `NoMatchingListenerHostname` and omitted from xDS by excluding conflict-losing listeners from route hostname filtering.
- Fixed the controller crash-looping when an extension manager's `backendResources` references a CRD that is not installed in the cluster. The CRD existence is now checked once at controller startup and cached in a field on the reconciler, following the same pattern already used for `ServiceImport`, `Backend`, and other optional CRDs. When the CRD is absent, both the watch and the reconcile list path are skipped; all other errors from the list call are returned so the reconcile is retried instead of publishing an incomplete resource snapshot.
- The global rate limit cluster is now built from the in-cluster `envoy-ratelimit` Service/EndpointSlices using EDS instead of resolving a static DNS hostname, so requests keep hitting rate limit service replicas correctly as they scale up or down. When the Service or its endpoints can't be discovered, Envoy Gateway falls back to the previous STRICT_DNS behavior.
Comment thread
kkk777-7 marked this conversation as resolved.
- Fixed the File and ALS access log sinks silently falling back to the default JSON fields when `telemetry.accessLog.settings[].format` sets `text` without `type`, which the API accepts.
- Fixed a `BackendTrafficPolicy` setting a `ConsistentHash` load balancer having no effect when it targets a `UDPRoute`. The cluster was configured with Maglev, but no hash policy was set on the UDP proxy listener filter, so Envoy had no hash key to compute and fell back to picking an upstream host at random for every UDP session. The source IP hash policy is now configured on the UDP proxy. Only the `SourceIP` consistent hash type applies to UDP, since headers, cookies and query parameters do not exist in a UDP datagram.
- Fixed controller panic when translating backend credential injection with an invalid header.
- Fixed the Wasm image permission cache key omitting the CA certificate, which allowed a permission check result to be reused across different TLS trust configurations.

## Performance improvements
- Improved reconcile performance by listing the extension manager's `resources` and `backendResources` once per GatewayClass instead of once per Gateway.

## Deprecations
-

## Other changes
- Added per-phase tracing spans to the Gateway API and xDS translators, each recording the size of the input it processed, so that a slow translation can be attributed to a specific phase — listener processing, HTTP and gRPC route processing, the main policy types, EnvoyPatchPolicy JSON patches, extension server hooks, and xDS resource validation — instead of showing up as one opaque multi-second span.