CVE-2026-41246Disclosure(projectcontour / contour)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.routes[].cookieRewritePolicies[].pathRewrite.value or spec.routes[].services[].cookieRewritePolicies[].pathRewrite.value that results in arbitrary code execution in the Envoy proxy. The cookie rewriting feature is internally implemented using Envoy's HTTP Lua filter. User-controlled values are interpolated into Lua source code using Go text/template without sufficient sanitization. The injected code only executes when processing traffic on the attacker's own route, which they already control. However, since Envoy runs as shared infrastructure, the injected code can also read Envoy's xDS client credentials from the filesystem or cause denial of service for other tenants sharing the Envoy instance. This vulnerability is fixed in v1.33.4, v1.32.5, and v1.31.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • contour

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
contour

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 104-2304-24
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 (Contour), Lua code injection, #CVE-2026-41246 (High) https://dailycve.com/contour-lua-code-injection-cve-2026-41246-high/

    Post summary

    The tweet announces the disclosure of a high‑severity Lua code injection vulnerability (CVE‑2026‑41246) affecting Contour, without providing proof‑of‑concept details or evidence of exploitation.

    0000035
    183 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41246 Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable t… https://www.cve.org/CVERecord?id=CVE-2026-41246

    Post summary

    The statement announces CVE‑2026‑41246, identifying affected Contour Kubernetes ingress controller versions and the vulnerable Cookie Rewriting feature, without detailing exploitation or remediation.

    00000105
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprojectcontourcontour-kubernetes-

Explore more