v1.33.10

envoyproxy/envoyv1.33.10Oct 13, 2025by publish-envoy[bot]

AI Summary

This release focuses on resolving dependency CVEs across Curl, gRPC, LuaJIT, and Kafka.

Key Highlights

  • Resolved CVE-2025-0725 for curl
  • Resolved CVEs for gRPC (2024-11407)
  • Resolved CVEs for luajit (2024-25176, 2024-25177, 2024-25178)
  • Resolved CVEs for kafka (2025-27817, 2025-27818)

Full Release Notes

**Summary of changes**:
* Security updates:

  Resolve dependency CVEs:
  - CVE-2025-0725: curl
  - CVE-2024-11407: gRPC
  - CVE-2024-25176: luajit
  - CVE-2024-25177: luajit
  - CVE-2024-25178: luajit
  - CVE-2025-27817: kafka
  - CVE-2025-27818: kafka

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.33.10
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.33.10/
**Release notes**:

https://www.envoyproxy.io/docs/envoy/v1.33.10/version_history/v1.33/v1.33.10
**Full changelog**:
    https://github.com/envoyproxy/envoy/compare/v1.33.9...v1.33.10

Signed-off-by: Ryan Northey <ryan@synca.io>
Signed-off-by: Rohit Agrawal <rohit.agrawal@databricks.com>