v3.6.24
Changed 1
- Bump google.golang.org/grpc to v1.82.1
Fixed 6
- Add missing ErrorRequestHeaders field to CRDs
- Remove unrelated error from nonexistent cert resolver log
- Disable Zstd support in the gzhttp wrapper
- Defer the CONNECT payload until the backend accepts the tunnel
- Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy
- Do not add back CONNECT requests to the pool
Security 1
- Fix vulnerability GHSA-3ccp-42pg-hgv6
Important: Please read the migration guide.
CVE fixed:
- Advisory GHSA-3ccp-42pg-hgv6
Bug fixes:
- [middleware, k8s/crd] Add missing ErrorRequestHeaders field to CRDs (#13498 @kevinpollet)
- [logs] Remove unrelated error from nonexistent cert resolver log (#13469 @ArthurHlt)
- [middleware] Disable Zstd support in the gzhttp wrapper (#13533 @kevinpollet)
- [server] Defer the CONNECT payload until the backend accepts the tunnel (#13542 @sdelicata)
- [server] Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy (#13543 @sdelicata)
- [server] Bump google.golang.org/grpc to v1.82.1 (#13551 @piscue)
- [server] Do not add back CONNECT requests to the pool (#13556 @kevinpollet)
Documentation: