- Multiple security vulnerabilities fixed including DoS attacks via unbounded caching, nil-pointer panics, path normalization bypass, and unauthenticated JSON decoder attacks
- New gRPC connection limiter configuration option (limits.grpc_max_conns_per_client) to prevent connection exhaustion attacks
- API Gateway now correctly handles service-router configurations that compose routes across different services, namespaces, or partitions
- New XDS configuration options for controlling server response headers on API Gateway HTTP listeners
Consul
tool22 releases · 12 support linesSupport lines
| Line | Latest | Status | End of life |
|---|---|---|---|
| 2.0 | 2.0.3 | supported | — |
| 1.22 | 1.22.7 | supported | — |
| 1.21 | 1.21.5 | supported | — |
| 1.20 | 1.20.6 | eol | 24 May 2026 |
| 1.19 | 1.19.2 | eol | 27 Oct 2025 |
| 1.18 | 1.18.2 | eol | 6 May 2025 |
| 1.17 | 1.17.4 | eol | 14 Oct 2024 |
| 1.16 | 1.16.7 | eol | 12 Jun 2024 |
| 1.15 | 1.15.11 | eol | 27 Feb 2024 |
| 1.14 | 1.14.11 | eol | 3 Nov 2023 |
| 1.13 | 1.13.9 | eol | 26 Jun 2023 |
| 1.12 | 1.12.9 | eol | 23 Feb 2023 |
Releases
- Alpine base image upgraded to address security vulnerabilities
- Serf and Memberlist dependencies updated to latest versions
- XDS now returns errors when L4 intention filters or mTLS cannot be enforced on inbound public listeners
- Fixed client certificate SDS block emission to only occur when both CertFile and KeyFile are configured
If using consul OSS version with consul-k8s, use Helm Chart version '2.0.2-oss' instead of '2.0.2' to resolve the missing RouteExtProc CRD issue.
- Security: Go upgraded to 1.26.4 and Envoy versions updated (1.37.4, 1.36.8, 1.35.12 supported; 1.38.2 added; 1.34.14 removed) to address vulnerabilities
- Fixed a bug where renaming a server could cause leader eviction and HTTP 500 errors on follower RPCs
- Fixed a security issue where x-forwarded-client-cert headers were not stripped from inbound HTTP requests
- Auth method TokenNameFormat field now accepts OIDC and JWT claim mapping values
Envoy version 1.34.14 is no longer supported and has been removed.
Upgrade Go to version 1.26.4. Update Envoy to a supported version (1.35.12, 1.36.8, 1.37.4, or 1.38.2); version 1.34.14 is no longer supported.
- Security patches for Envoy, Go runtime, curl, and UBI base images address multiple CVEs
- HTTP request path normalization on API Gateway and terminating gateway prevents L7 intention RBAC bypass (CVE-2024-10005)
- New enterprise features including global rate limiting, multi-port service support, and Cyberark WIM CA provider
- API Gateway now supports SDS certificates, gateway-level upstream limits, and improved XDS generation for peered deployments
- The changelog for this release gives no detail.
No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗