Skip to content

Releases: envoyproxy/envoy

v1.39.3

Choose a tag to compare

@publish-envoy publish-envoy released this 06 Oct 18:22

Summary of changes:

  • Security fixes:
    • GHSA-8vc2-jrm4-835w:
      oauth2: crash on requests without a :path header (i.e. CONNECT). The filter now rejects such requests with 400.
    • GHSA-47vj-9r25-wv5j:
      api_key_auth: crash when hide_credentials is enabled with a query key source and a request without a :path header (i.e. CONNECT) is authenticated via another key source.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.3
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.3/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.3/version_history/v1.39/v1.39.3
Full changelog:
v1.39.2...v1.39.3

Signed-off-by: wbpcode wbphub@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

v1.38.6

Choose a tag to compare

@publish-envoy publish-envoy released this 06 Oct 16:39

Summary of changes:

  • Security fixes:
    • GHSA-8vc2-jrm4-835w:
      oauth2: crash on requests without a :path header (i.e. CONNECT). The filter now rejects such requests with 400.
    • GHSA-47vj-9r25-wv5j:
      api_key_auth: crash when hide_credentials is enabled with a query key source and a request without a :path header (i.e. CONNECT) is authenticated via another key source.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.6
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.6/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.6/version_history/v1.38/v1.38.6
Full changelog:
v1.38.5...v1.38.6

Signed-off-by: wbpcode wbphub@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

v1.37.8

Choose a tag to compare

@publish-envoy publish-envoy released this 06 Oct 14:43

Summary of changes:

  • Security fixes:
    • GHSA-8vc2-jrm4-835w:
      oauth2: crash on requests without a :path header (i.e. CONNECT). The filter now rejects such requests with 400.
    • GHSA-47vj-9r25-wv5j:
      api_key_auth: crash when hide_credentials is enabled with a query key source and a request without a :path header (i.e. CONNECT) is authenticated via another key source.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.8
Docs:
https://www.envoyproxy.io/docs/envoy/v1.37.8/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.37.8/version_history/v1.37/v1.37.8
Full changelog:
v1.37.7...v1.37.8

Signed-off-by: wbpcode wbphub@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

v1.36.12

Choose a tag to compare

@publish-envoy publish-envoy released this 06 Oct 13:28

Summary of changes:

  • Security fixes:
    • GHSA-8vc2-jrm4-835w:
      oauth2: crash on requests without a :path header (i.e. CONNECT). The filter now rejects such requests with 400.
    • GHSA-47vj-9r25-wv5j:
      api_key_auth: crash when hide_credentials is enabled with a query key source and a request without a :path header (i.e. CONNECT) is authenticated via another key source.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.12
Docs:
https://www.envoyproxy.io/docs/envoy/v1.36.12/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.36.12/version_history/v1.36/v1.36.12
Full changelog:
v1.36.11...v1.36.12

Signed-off-by: wbpcode wbphub@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

v1.39.2

Choose a tag to compare

@publish-envoy publish-envoy released this 01 Oct 18:48

Summary of changes:

  • Security fixes:

    • CVE-2026-35189: tls: updated BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes.
  • Build/packaging:

    • Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
    • Moved Debian .changes and release checksum signing into the Bazel release assembly, with an audit of signing actions.
    • Refreshed the Ubuntu build and distroless Docker base images.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.2
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.2/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.2/version_history/v1.39/v1.39.2
Full changelog:
v1.39.1...v1.39.2

Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io

v1.38.5

Choose a tag to compare

@publish-envoy publish-envoy released this 01 Oct 16:53

Summary of changes:

  • Security fixes:

    • CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. The BoringSSL FIPS build (--config=boringssl-fips) does not receive this patch.
  • Build/packaging:

    • Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
    • Moved Debian .changes and release checksum signing into the Bazel release assembly, with an audit of signing actions.
    • Refreshed the Ubuntu build image.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.5
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.5/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.5/version_history/v1.38/v1.38.5
Full changelog:
v1.38.4...v1.38.5

Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io

v1.37.7

Choose a tag to compare

@publish-envoy publish-envoy released this 01 Oct 14:59

Summary of changes:

  • Security fixes:

    • CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. The BoringSSL FIPS build (--define boringssl=fips) does not receive this patch.
  • Build/packaging:

    • Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
    • Moved Debian .changes and release checksum signing into the Bazel release assembly, with an audit of signing actions.
    • Refreshed the Ubuntu build image.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.7
Docs:
https://www.envoyproxy.io/docs/envoy/v1.37.7/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.37.7/version_history/v1.37/v1.37.7
Full changelog:
v1.37.6...v1.37.7

Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io

v1.36.11

Choose a tag to compare

@publish-envoy publish-envoy released this 01 Oct 13:05

Summary of changes:

  • Security fixes:

    • CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. Note that the FIPS build is not patched.
  • Build/packaging:

    • Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.11
Docs:
https://www.envoyproxy.io/docs/envoy/v1.36.11/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.36.11/version_history/v1.36/v1.36.11
Full changelog:
v1.36.10...v1.36.11

Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io

v1.39.1

Choose a tag to compare

@publish-envoy publish-envoy released this 27 Aug 01:18

Summary of changes:

  • Security fixes:

    • CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with envoy.reloadable_features.strip_path_parameters_per_segment.
    • CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames.
    • CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag.
    • CVE-2026-73546: admin: sanitize stat names before converting them to HTML. Guarded by envoy.reloadable_features.sanitize_html_stats_names.
    • CVE-2026-73547: ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
    • CVE-2026-73548: http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with envoy.reloadable_features.http_pause_generic_upgrade_request_body.
    • CVE-2026-73549: quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
    • CVE-2026-73550: http2: dropped Host headers now count towards request header map size and count limits. Revert with envoy.reloadable_features.http2_track_size_of_dropped_host_header.
    • CVE-2026-73551: url normalization: strip path parameters from dot and dotdot segments (/.;, /..;) so canonicalization interprets them correctly. Applies only when normalize_path is enabled; revert with envoy.reloadable_features.strip_dotdot_segments_with_parameters.
    • CVE-2026-73552: safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with envoy.reloadable_features.re2_use_latin1_mode.
    • CVE-2026-73553: rbac: RBAC path matching now respects the route's ignore_path_parameters_in_path_matching, preventing authz bypass via appended path parameters. Revert with envoy.reloadable_features.rbac_respect_ignore_path_parameters.
    • CVE-2026-50572: ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
    • CVE-2026-48521: http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.
  • Bug fixes:

    • http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via addDecodedData()/addEncodedData() immediately before returning Continue was silently dropped, corrupting large streamed bodies. Revert with envoy.reloadable_features.filter_manager_forward_added_data_on_continue.
    • ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
    • tls: fixed a memory leak in the OpenSSL compatibility layer where SSL_get0_peer_certificates() leaked an X509 refcount per call, preventing certificates from being freed on connection close.
    • tls: fixed a bug where OpenSSL used glibc's allocator instead of tcmalloc, operating on a separate heap and making OpenSSL allocations invisible to tcmalloc heap profiling.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.1
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.1/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.1/version_history/v1.39/v1.39.1
Full changelog:
v1.39.0...v1.39.1

Signed-off-by: Yan Avlasov yavlasov@google.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
Signed-off-by: Ryan Northey ryan@synca.io

v1.38.4

Choose a tag to compare

@publish-envoy publish-envoy released this 26 Aug 23:51

Summary of changes:

  • Security fixes:

    • CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with envoy.reloadable_features.strip_path_parameters_per_segment.
    • CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames.
    • CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag.
    • CVE-2026-73546: admin: sanitize stat names before converting them to HTML. Guarded by envoy.reloadable_features.sanitize_html_stats_names.
    • CVE-2026-73547: ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
    • CVE-2026-73548: http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with envoy.reloadable_features.http_pause_generic_upgrade_request_body.
    • CVE-2026-73549: quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
    • CVE-2026-73550: http2: dropped Host headers now count towards request header map size and count limits. Revert with envoy.reloadable_features.http2_track_size_of_dropped_host_header.
    • CVE-2026-73551: url normalization: strip path parameters from dot and dotdot segments (/.;, /..;) so canonicalization interprets them correctly. Applies only when normalize_path is enabled; revert with envoy.reloadable_features.strip_dotdot_segments_with_parameters.
    • CVE-2026-73552: safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with envoy.reloadable_features.re2_use_latin1_mode.
    • CVE-2026-73553: rbac: RBAC path matching now respects the route's ignore_path_parameters_in_path_matching, preventing authz bypass via appended path parameters. Revert with envoy.reloadable_features.rbac_respect_ignore_path_parameters.
    • CVE-2026-50572: ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
    • CVE-2026-48521: http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.
  • Bug fixes:

    • http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via addDecodedData()/addEncodedData() immediately before returning Continue was silently dropped, corrupting large streamed bodies. Revert with envoy.reloadable_features.filter_manager_forward_added_data_on_continue.
    • ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
    • router: fixed a lifetime bug in dynamic forward proxy async host selection when the cluster is removed while lookup is still pending.
    • tls: fixed a memory leak in the OpenSSL compatibility layer where SSL_get0_peer_certificates() leaked an X509 refcount per call, preventing certificates from being freed on connection close.
    • tls: fixed a bug where OpenSSL used glibc's allocator instead of tcmalloc, operating on a separate heap and making OpenSSL allocations invisible to tcmalloc heap profiling.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.4
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.4/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.4/version_history/v1.38/v1.38.4
Full changelog:
v1.38.3...v1.38.4

Signed-off-by: Yan Avlasov yavlasov@google.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
Signed-off-by: Ryan Northey ryan@synca.io