Envoy Gateway 1.9.1 tightens security and complicates upgrade from 1.9.0
Envoy Gateway 1.9.1 restores the 15-second initial SDS/RDS fetch timeout that v1.9.0 set to zero, enables AES-256-GCM for OAuth2/OIDC session cookies and fixes CVE-2026-47775. Users on v1.9.0 are advised to follow a careful rolling-update strategy, since SDS config changes can leave TLS proxies without certificates.
- Initial SDS/RDS fetch timeout restored to 15 seconds from zero in v1.9.0
- AES-256-GCM enabled for OAuth2/OIDC cookies, CVE-2026-47775 fixed
- Implicit HTTPS-to-HTTP fallback removed for OCI Wasm image pulls
- Per-phase tracing spans added for Gateway API and xDS translation
Read next
Software