v1.33.3

envoyproxy/envoyv1.33.3May 7, 2025by publish-envoy[bot]

AI Summary

Addresses the critical RBAC URI template bypass vulnerability for the 1.33 branch.

Key Highlights

  • Fixed CVE-2025-46821 (RBAC uri_template bypass)

Full Release Notes

**Summary of changes**:

* Security:
  - [CVE-2025-46821](https://github.com/envoyproxy/envoy/security/advisories/GHSA-c7cm-838g-6g67): Bypass of RBAC `uri_template` permission.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.33.3
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.33.3/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.33.3/version_history/v1.33/v1.33.3
**Full changelog**:
    https://github.com/envoyproxy/envoy/compare/v1.33.2...v1.33.3

Signed-off-by: Yan Avlasov <yavlasov@google.com>
Signed-off-by: Boteng Yao <boteng@google.com>
Signed-off-by: Ryan Northey <ryan@synca.io>