v1.6.7

Date: April 27, 2026

Breaking changes

Security updates

  • Bumped google.golang.org/grpc to v1.79.3 to address CVE-2026-33186 (Critical, gRPC-Go authorization bypass via non-canonical HTTP/2 :path header).
  • Bumped go.opentelemetry.io/otel/sdk to v1.40.0 to address CVE-2026-24051 (High, OpenTelemetry Go SDK path hijacking on macOS/Darwin).

New features

Bug fixes

  • Fixed a control plane panic caused by concurrent Status mutation racing with the watchable Map coalesce goroutine.
  • Fixed status conditions not being updated when a route is rejected due to multiple errors.
  • Fixed unresolved or unsupported HTTPRoute filters using BackendNotFound as the ResolvedRefs reason; they now correctly use UnsupportedValue.
  • Fixed benchmark JSON report emitting 0 for p99 and p999 percentiles by using the nearest Nighthawk histogram percentiles.

Performance improvements

  • Introduced a translator context with preprocessed resource maps in the Gateway API translator, reducing translation time by up to ~45% on large workloads.

Deprecations

Other changes