v1.32.6
envoyproxy/envoyv1.32.6May 7, 2025by publish-envoy[bot]
AI Summary
This release addresses a critical security vulnerability (CVE-2025-46821) related to RBAC `uri_template` permission bypass. It includes Docker images and documentation updates.
Key Highlights
- Security fix for CVE-2025-46821: Bypass of RBAC `uri_template` permission.
- Docker images available on Docker Hub.
- Documentation and changelog links provided.
Full Release Notes
repo: Release v1.32.6
**Summary of changes**:
* Security:
- [CVE-2025-46821](https://github.com/envoyproxy/envoy/security/advisories/GHSA-c7cm-838g-6g67): Bypass of RBAC `uri_template` permission.
**Docker images**:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.32.6
**Docs**:
https://www.envoyproxy.io/docs/envoy/v1.32.6/
**Release notes**:
https://www.envoyproxy.io/docs/envoy/v1.32.6/version_history/v1.32/v1.32.6
**Full changelog**:
https://github.com/envoyproxy/envoy/compare/v1.32.5...v1.32.6
Signed-off-by: Yan Avlasov <yavlasov@google.com>
Signed-off-by: Boteng Yao <boteng@google.com>
Signed-off-by: Ryan Northey <ryan@synca.io>