RepoJournal
HashiCorp

@hashicorp

Terraform, Vault, Consul - infra-as-code for ops teams

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

One email a day. Unsubscribe in one click.

Pick a date

Topics: Go Infrastructure Full archive →

The Wire · Showcase

HASHICORP PATCHES MARKDOWN DOS, SHIPS API GATEWAY AUTH CONTROLS

By RepoJournal · Filed · About HashiCorp

1 person shipped this

Consul-K8s locked down a remote denial-of-service vulnerability in Markdown while simultaneously shipping external authorization support to the API Gateway.

The security fix [1] upgraded Markdown from 3.3.7 to 3.8.1 to patch CVE-2025-69534, an uncaught AssertionError that crashes processors parsing malformed HTML input from untrusted sources. MkDocs rode along from 1.4.3 to 1.6.1 because older versions pinned incompatible Markdown versions. This is a ship-now patch for anything running the vendored gateway-api 0.7.1 docs toolchain. On the feature side, Consul-K8s merged external authorization (`ext_authz`) support for the API Gateway [2], adding a new `RouteAuthFilter` CRD that lets operators override gateway-wide auth policies on a per-route basis. A companion PR [3] enables the `RouteExtProc` CRD for Consul Enterprise, expanding the authorization chain to multi-port configurations. Homebrew tap saw five routine version bumps across the estate: Boundary Enterprise 1.0.1, Consul Terraform Sync 0.9.1, Dataplane 2.0.2, envconsul 0.14.0, and Consul ESM 0.11.0 [4][5][6][7][8]. In the Packer universe, the team dropped an unmaintained cryptography dependency by upgrading go-github from v33 to v75 [9], eliminating GO-2026-5932 in `golang.org/x/crypto/openpgp` which has no patch available and was only pulled in transitively. Packer-plugin-amazon released 1.8.2 to stabilize crypto version conflicts [10], though a follow-up PR nudged x/crypto to 0.54.0 [11] after discovering compatibility issues with the initial downgrade.

One email a day. Unsubscribe in one click.

Action items

References

  1. [1] security: upgrade Python deps in gateway-api 0.7.1 module (4 advisories) (#5473) hashicorp/consul-k8s
  2. [2] ext_authz support for api-gateway (#5444) hashicorp/consul-k8s
  3. [3] Enabling routeextproc crd and addition of it to httproutes ↗ hashicorp/consul-k8s
  4. [4] Bump boundary-enterprise to 1.0.1+ent hashicorp/homebrew-tap
  5. [5] Bump consul-terraform-sync to 0.9.1 hashicorp/homebrew-tap
  6. [6] Bump consul-dataplane to 2.0.2 hashicorp/homebrew-tap
  7. [7] Bump envconsul to 0.14.0 hashicorp/homebrew-tap
  8. [8] Bump consul-esm to 0.11.0 hashicorp/homebrew-tap
  9. [9] security: drop x/crypto/openpgp by upgrading go-github v33 -> v75 (#13676) hashicorp/packer
  10. [10] release: update version to 1.8.2 and remove prerelease tag (#690) hashicorp/packer-plugin-amazon
  11. [11] ADDED THE 0.54.0 crypto version (#692) hashicorp/packer-plugin-amazon

Quick answers

What shipped in HashiCorp on July 10, 2026?
Consul-K8s locked down a remote denial-of-service vulnerability in Markdown while simultaneously shipping external authorization support to the API Gateway. In total, 14 commits and 11 pull requests landed.
Who contributed to HashiCorp on July 10, 2026?
1 developer shipped this update, including pajay-rao.
What were the notable HashiCorp updates?
security: upgrade Python deps in gateway-api 0.7.1 module (4 advisories) (#5473), ext_authz support for api-gateway (#5444), and Enabling routeextproc crd and addition of it to httproutes.

More from @hashicorp

Daily updates, in your inbox

Follow HashiCorp

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

One email a day. Unsubscribe in one click. Read a past issue →

Elsewhere on the wire

Want every project, not just this one?

We use privacy-friendly analytics (Google Analytics, IP-anonymized) to see which pages help readers. No ads, and we never sell your data. See our Privacy Policy.