v1.33.8

envoyproxy/envoyv1.33.8Sep 2, 2025by publish-envoy[bot]

AI Summary

This release addresses a critical security vulnerability in OAuth cookie handling identified as CVE-2025-55162. It serves as a patch release to mitigate potential security risks for users on the v1.33 branch.

Key Highlights

  • Fixed OAuth cookie issue (CVE-2025-55162)
  • Security advisory GHSA-95j4-hw7f-v2rh

Full Release Notes

**Summary of changes**:

* Security fixes:
  - Fix for OAuth cookie issue [CVE-2025-55162](https://github.com/envoyproxy/envoy/security/advisories/GHSA-95j4-hw7f-v2rh).

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.33.8
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.33.8/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.33.8/version_history/v1.33/v1.33.8
**Full changelog**:
    https://github.com/envoyproxy/envoy/compare/v1.33.7...v1.33.8

Signed-off-by: yanavlasov <yavlasov@google.com>
Signed-off-by: Ryan Northey <ryan@synca.io>