Skip to content

Commit 14197ab

Browse files
publish-envoy[bot]phlax
authored andcommitted
repo: Release v1.33.14
**Summary of changes**: * Security updates: Resolve dependency CVEs: - c-ares/CVE-2025-0913: Use after free can crash Envoy due to malfunctioning or compromised DNS. While a potentially severe bug in some cloud environments, this has limited exploitability as any attacker would require control of DNS. Envoy advisory is here GHSA-fg9g-pvc4-776f **Docker images**: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.33.14 **Docs**: https://www.envoyproxy.io/docs/envoy/v1.33.14/ **Release notes**: https://www.envoyproxy.io/docs/envoy/v1.33.14/version_history/v1.33/v1.33.14 **Full changelog**: v1.33.13...v1.33.14
1 parent 58231a3 commit 14197ab

File tree

4 files changed

+3
-16
lines changed

4 files changed

+3
-16
lines changed

VERSION.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
1.33.14-dev
1+
1.33.14

changelogs/current.yaml

Lines changed: 1 addition & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,6 @@
1-
date: Pending
2-
3-
behavior_changes:
4-
# *Changes that are expected to cause an incompatibility if applicable; deployment changes are likely required*
5-
6-
minor_behavior_changes:
7-
# *Changes that may cause incompatibilities for some users, but should not for most*
1+
date: December 9, 2025
82

93
bug_fixes:
10-
# *Changes expected to improve the state of the world and are unlikely to have negative effects*
114
- area: dns
125
change: |
136
Update c-ares to version 1.34.6 to resolve CVE-2025-0913.
@@ -16,14 +9,8 @@ bug_fixes:
169
1710
advisory: https://github.com/envoyproxy/envoy/security/advisories/GHSA-fg9g-pvc4-776f.
1811
19-
20-
removed_config_or_runtime:
21-
# *Normally occurs at the end of the* :ref:`deprecation period <deprecated>`
22-
2312
new_features:
2413
- area: dns
2514
change: |
2615
Update c-ares to version 1.34.4. This upgrade exposes ``ares_reinit()`` which allows the reinitialization of c-ares channels,
2716
among several other new features, bug-fixes, etc.
28-
29-
deprecated:

docs/inventories/v1.33/objects.inv

22 Bytes
Binary file not shown.

docs/versions.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,4 +26,4 @@
2626
"1.30": 1.30.11
2727
"1.31": 1.31.10
2828
"1.32": 1.32.13
29-
"1.33": 1.33.12
29+
"1.33": 1.33.13

0 commit comments

Comments
 (0)