Envoy Gateway released version 1.9.1 on August 28. This maintenance release focuses on security, upgrade reliability, and operational correctness. It reverses a change made in version 1.9.0 regarding secret and endpoint fetching, includes fixes for several security issues, and adds more granular observability into Gateway API and xDS translation.
A significant change in 1.9.1 involves the initial fetch timeout for Secret Discovery Service (SDS) and Route Discovery Service (RDS). Version 1.9.0 had set this timeout to zero, which could cause clusters to remain in a warming state indefinitely if a Secret or endpoint was missing. This prevented CDS updates and delayed health checks. Version 1.9.1 restores the default 15-second timeout, returning to the behavior of v1.8.x.
Upgrading from 1.9.0 is complex. Changing the SDS configuration during a controller upgrade can cause an Envoy issue where TLS listeners become active without certificates, leading to failed TLS handshakes. Backend TLS configurations and global rate-limit services can experience similar problems. A GitHub issue described an outage where long-running Envoy proxies lost downstream TLS certificates and stopped serving HTTPS traffic, requiring manual restarts.
For users on v1.8.x, the project recommends upgrading directly to v1.9.1, skipping v1.9.0. Existing v1.9.0 deployments require a rolling-update configuration to replace proxy pods quickly. This method requires sufficient cluster capacity and can interrupt existing connections, particularly long-lived WebSocket and gRPC connections.
Security is a key focus of this release. Envoy Gateway now enables AES-256-GCM for OAuth2/OIDC session-cookie encryption. It also removes support for the legacy AES-256-CBC decryption path, which addresses the padding-oracle vulnerability identified as CVE-2026-47775.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Envoy Gateway released version 1.9.1, a maintenance update that reverts a change to secret and endpoint fetching from version 1.9.0, fixes security issues, and improves observability. The update addresses a difficult upgrade path for users on 1.9.0 and a padding-oracle vulnerability.