Envoy Gateway 1.9.1 Fixes Upgrade Issues and Security Vulnerabilities

The latest Envoy Gateway version, 1.9.1, launched on August 28, focuses on reinforcing security measures and ensuring smoother operations following the initial v1.9 rollout. This update undoes a problematic alteration from the earlier version related to secret retrieval and endpoint discovery, which had created stability concerns. It also patches multiple security flaws and enhances visibility into Gateway API and xDS translation processes.
Resolving Upgrade Complications
The primary adjustment involves the initial timeout period for the Secret Discovery Service (SDS) and Route Discovery Service (RDS). When version 1.9.0 set this timeout to zero, clusters became stuck waiting for unavailable secrets or endpoints, remaining in a suspended state. This blocked Cluster Discovery Service updates and delayed health checks. Now, 1.9.1 reinstates the original 15-second timeout, aligning with the behavior seen in the 1.8.x series.
Existing users of v1.9.0 face additional challenges. The project cautions that modifying SDS settings during a controller upgrade may cause issues for proxies still active while the new controller deploys. In such cases, TLS listeners could activate without proper certificates, leading to failed new TLS handshakes. Similar certificate or CA problems may also emerge in backend TLS configurations and the global rate-limiting system.
A production user reported an incident where long-running proxies lost downstream TLS certificates, halting HTTPS traffic entirely. Restoring service required manual proxy restarts. The problem traced back to how new SDS subscriptions were processed and the timeout adjustment introduced in v1.9.0.
For those on v1.8.x, the team advises upgrading directly to 1.9.1, bypassing 1.9.0 entirely. Current 1.9.0 deployments need careful handling. The recommended approach involves a rolling update that quickly replaces proxy pods, though this demands sufficient cluster resources and may disrupt active connections—especially persistent WebSocket and gRPC sessions—as pods are refreshed.
Read Also: New AI model delivers fast
Bolstering Security Protections
Security enhancements form another key focus of this release. Envoy Gateway now enforces AES-256-GCM encryption for OAuth2/OIDC session cookies while eliminating support for the outdated AES-256-CBC decryption method. This resolves the padding-oracle vulnerability tracked as CVE-2026-47775. Users with active sessions under the older encryption will need to re-authenticate after upgrading. Custom Envoy bootstrap configurations must explicitly set the corresponding runtime parameters.
Additional security measures have been implemented. OIDC issuer URLs now undergo stricter validation, while OCI Wasm image downloads no longer silently downgrade from HTTPS to HTTP. A security-context flaw involving tenant-provided EnvoyProxy configurations has also been corrected. Previously, tenant-supplied Kubernetes security contexts could override Envoy Gateway’s hardened defaults, potentially removing safeguards like privileged execution or root access restrictions.
The Wasm-related changes carry significant supply-chain security implications. Previously, if an OCI registry rejected HTTPS requests, Envoy Gateway would default to unencrypted HTTP, exposing systems to on-path attacks delivering malicious Wasm code. Version 1.9.1 eliminates this automatic fallback, HTTP is now only permitted for registries explicitly marked as insecure.
Controller and Traffic Management Updates
Several behind-the-scenes improvements refine controller functionality and traffic management. OIDC flow cookies are now restricted to the redirect path, preventing abandoned authentication cookies from spreading unnecessarily. The system now automatically monitors namespace label changes, allowing route acceptance to be reassessed without controller restarts. Other fixes address hostname conflicts, crashes caused by missing optional CRDs, and incorrect UDP route hashing behavior.
One subtle but valuable change benefits platform engineering teams. Envoy Gateway now generates detailed tracing spans for each phase of Gateway API and xDS translation. Instead of viewing slow translations as undifferentiated delays, operators can pinpoint bottlenecks across listener processing, HTTP/GRPC routes, policy enforcement, EnvoyPatchPolicy handling, extension hooks, and xDS validation.
