Repository navigation
Releases: envoyproxy/envoy
Release list
v1.39.3
Summary of changes:
- Security fixes:
- GHSA-8vc2-jrm4-835w:
oauth2: crash on requests without a:pathheader (i.e. CONNECT). The filter now rejects such requests with400. - GHSA-47vj-9r25-wv5j:
api_key_auth: crash whenhide_credentialsis enabled with aquerykey source and a request without a:pathheader (i.e. CONNECT) is authenticated via another key source.
- GHSA-8vc2-jrm4-835w:
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.3
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.3/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.3/version_history/v1.39/v1.39.3
Full changelog:
v1.39.2...v1.39.3
Signed-off-by: wbpcode wbphub@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
v1.38.6
Summary of changes:
- Security fixes:
- GHSA-8vc2-jrm4-835w:
oauth2: crash on requests without a:pathheader (i.e. CONNECT). The filter now rejects such requests with400. - GHSA-47vj-9r25-wv5j:
api_key_auth: crash whenhide_credentialsis enabled with aquerykey source and a request without a:pathheader (i.e. CONNECT) is authenticated via another key source.
- GHSA-8vc2-jrm4-835w:
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.6
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.6/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.6/version_history/v1.38/v1.38.6
Full changelog:
v1.38.5...v1.38.6
Signed-off-by: wbpcode wbphub@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
v1.37.8
Summary of changes:
- Security fixes:
- GHSA-8vc2-jrm4-835w:
oauth2: crash on requests without a:pathheader (i.e. CONNECT). The filter now rejects such requests with400. - GHSA-47vj-9r25-wv5j:
api_key_auth: crash whenhide_credentialsis enabled with aquerykey source and a request without a:pathheader (i.e. CONNECT) is authenticated via another key source.
- GHSA-8vc2-jrm4-835w:
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.8
Docs:
https://www.envoyproxy.io/docs/envoy/v1.37.8/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.37.8/version_history/v1.37/v1.37.8
Full changelog:
v1.37.7...v1.37.8
Signed-off-by: wbpcode wbphub@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
v1.36.12
Summary of changes:
- Security fixes:
- GHSA-8vc2-jrm4-835w:
oauth2: crash on requests without a:pathheader (i.e. CONNECT). The filter now rejects such requests with400. - GHSA-47vj-9r25-wv5j:
api_key_auth: crash whenhide_credentialsis enabled with aquerykey source and a request without a:pathheader (i.e. CONNECT) is authenticated via another key source.
- GHSA-8vc2-jrm4-835w:
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.12
Docs:
https://www.envoyproxy.io/docs/envoy/v1.36.12/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.36.12/version_history/v1.36/v1.36.12
Full changelog:
v1.36.11...v1.36.12
Signed-off-by: wbpcode wbphub@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
v1.39.2
Summary of changes:
-
Security fixes:
- CVE-2026-35189: tls: updated BoringSSL to fix excessive memory allocation when parsing certificates with
nameRelativeToCRLIssuerCRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes.
- CVE-2026-35189: tls: updated BoringSSL to fix excessive memory allocation when parsing certificates with
-
Build/packaging:
- Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
- Moved Debian
.changesand release checksum signing into the Bazel release assembly, with an audit of signing actions. - Refreshed the Ubuntu build and distroless Docker base images.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.2
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.2/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.2/version_history/v1.39/v1.39.2
Full changelog:
v1.39.1...v1.39.2
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
v1.38.5
Summary of changes:
-
Security fixes:
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
nameRelativeToCRLIssuerCRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. The BoringSSL FIPS build (--config=boringssl-fips) does not receive this patch.
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
-
Build/packaging:
- Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
- Moved Debian
.changesand release checksum signing into the Bazel release assembly, with an audit of signing actions. - Refreshed the Ubuntu build image.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.5
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.5/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.5/version_history/v1.38/v1.38.5
Full changelog:
v1.38.4...v1.38.5
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
v1.37.7
Summary of changes:
-
Security fixes:
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
nameRelativeToCRLIssuerCRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. The BoringSSL FIPS build (--define boringssl=fips) does not receive this patch.
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
-
Build/packaging:
- Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
- Moved Debian
.changesand release checksum signing into the Bazel release assembly, with an audit of signing actions. - Refreshed the Ubuntu build image.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.7
Docs:
https://www.envoyproxy.io/docs/envoy/v1.37.7/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.37.7/version_history/v1.37/v1.37.7
Full changelog:
v1.37.6...v1.37.7
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
v1.36.11
Summary of changes:
-
Security fixes:
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
nameRelativeToCRLIssuerCRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. Note that the FIPS build is not patched.
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
-
Build/packaging:
- Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.11
Docs:
https://www.envoyproxy.io/docs/envoy/v1.36.11/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.36.11/version_history/v1.36/v1.36.11
Full changelog:
v1.36.10...v1.36.11
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
v1.39.1
Summary of changes:
-
Security fixes:
- CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with
envoy.reloadable_features.strip_path_parameters_per_segment. - CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames.
- CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag.
- CVE-2026-73546: admin: sanitize stat names before converting them to HTML. Guarded by
envoy.reloadable_features.sanitize_html_stats_names. - CVE-2026-73547: ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
- CVE-2026-73548: http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with
envoy.reloadable_features.http_pause_generic_upgrade_request_body. - CVE-2026-73549: quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
- CVE-2026-73550: http2: dropped
Hostheaders now count towards request header map size and count limits. Revert withenvoy.reloadable_features.http2_track_size_of_dropped_host_header. - CVE-2026-73551: url normalization: strip path parameters from dot and dotdot segments (
/.;,/..;) so canonicalization interprets them correctly. Applies only whennormalize_pathis enabled; revert withenvoy.reloadable_features.strip_dotdot_segments_with_parameters. - CVE-2026-73552: safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with
envoy.reloadable_features.re2_use_latin1_mode. - CVE-2026-73553: rbac: RBAC path matching now respects the route's
ignore_path_parameters_in_path_matching, preventing authz bypass via appended path parameters. Revert withenvoy.reloadable_features.rbac_respect_ignore_path_parameters. - CVE-2026-50572: ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
- CVE-2026-48521: http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.
- CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with
-
Bug fixes:
- http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via
addDecodedData()/addEncodedData()immediately before returningContinuewas silently dropped, corrupting large streamed bodies. Revert withenvoy.reloadable_features.filter_manager_forward_added_data_on_continue. - ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
- tls: fixed a memory leak in the OpenSSL compatibility layer where
SSL_get0_peer_certificates()leaked anX509refcount per call, preventing certificates from being freed on connection close. - tls: fixed a bug where OpenSSL used glibc's allocator instead of tcmalloc, operating on a separate heap and making OpenSSL allocations invisible to tcmalloc heap profiling.
- http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.1
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.1/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.1/version_history/v1.39/v1.39.1
Full changelog:
v1.39.0...v1.39.1
Signed-off-by: Yan Avlasov yavlasov@google.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
Signed-off-by: Ryan Northey ryan@synca.io
v1.38.4
Summary of changes:
-
Security fixes:
- CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with
envoy.reloadable_features.strip_path_parameters_per_segment. - CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames.
- CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag.
- CVE-2026-73546: admin: sanitize stat names before converting them to HTML. Guarded by
envoy.reloadable_features.sanitize_html_stats_names. - CVE-2026-73547: ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
- CVE-2026-73548: http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with
envoy.reloadable_features.http_pause_generic_upgrade_request_body. - CVE-2026-73549: quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
- CVE-2026-73550: http2: dropped
Hostheaders now count towards request header map size and count limits. Revert withenvoy.reloadable_features.http2_track_size_of_dropped_host_header. - CVE-2026-73551: url normalization: strip path parameters from dot and dotdot segments (
/.;,/..;) so canonicalization interprets them correctly. Applies only whennormalize_pathis enabled; revert withenvoy.reloadable_features.strip_dotdot_segments_with_parameters. - CVE-2026-73552: safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with
envoy.reloadable_features.re2_use_latin1_mode. - CVE-2026-73553: rbac: RBAC path matching now respects the route's
ignore_path_parameters_in_path_matching, preventing authz bypass via appended path parameters. Revert withenvoy.reloadable_features.rbac_respect_ignore_path_parameters. - CVE-2026-50572: ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
- CVE-2026-48521: http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.
- CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with
-
Bug fixes:
- http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via
addDecodedData()/addEncodedData()immediately before returningContinuewas silently dropped, corrupting large streamed bodies. Revert withenvoy.reloadable_features.filter_manager_forward_added_data_on_continue. - ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
- router: fixed a lifetime bug in dynamic forward proxy async host selection when the cluster is removed while lookup is still pending.
- tls: fixed a memory leak in the OpenSSL compatibility layer where
SSL_get0_peer_certificates()leaked anX509refcount per call, preventing certificates from being freed on connection close. - tls: fixed a bug where OpenSSL used glibc's allocator instead of tcmalloc, operating on a separate heap and making OpenSSL allocations invisible to tcmalloc heap profiling.
- http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.4
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.4/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.4/version_history/v1.38/v1.38.4
Full changelog:
v1.38.3...v1.38.4
Signed-off-by: Yan Avlasov yavlasov@google.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
Signed-off-by: Ryan Northey ryan@synca.io