E

Envoy Proxy

E
Envoy Proxy Networking v1.37.7

v1.37.7

Summary of changes: Security fixes: CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. The BoringSSL FIPS build (--define boringssl=fips) does not receive this patch. Build/packaging: Removed Debian bullseye (11) packagi…

E
Envoy Proxy Networking v1.38.5

v1.38.5

Summary of changes: Security fixes: CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. The BoringSSL FIPS build (--config=boringssl-fips) does not receive this patch. Build/packaging: Removed Debian bullseye (11) packagi…

E
Envoy Proxy Networking v1.39.2

v1.39.2

Summary of changes: Security fixes: CVE-2026-35189: tls: updated BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. Build/packaging: Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on t…

E
Envoy Proxy Networking v1.36.11

v1.36.11

Summary of changes: Security fixes: CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. Note that the FIPS build is not patched. Build/packaging: Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its…

E
Envoy Proxy Networking v1.36.10

v1.36.10

Summary of changes: Security fixes: CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with envoy.reloadable_features.strip_path_parameters_per_segment. CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames. CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag…

E
Envoy Proxy Networking v1.37.6

v1.37.6

Summary of changes: Security fixes: CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with envoy.reloadable_features.strip_path_parameters_per_segment. CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames. CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag…

E
Envoy Proxy Networking v1.38.4

v1.38.4

Summary of changes: Security fixes: CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with envoy.reloadable_features.strip_path_parameters_per_segment. CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames. CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag…

E
Envoy Proxy Networking v1.39.1

v1.39.1

Summary of changes: Security fixes: CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with envoy.reloadable_features.strip_path_parameters_per_segment. CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames. CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag…

E
Envoy Proxy Networking v1.36.9

v1.36.9

Summary of changes: Security fixes: CVE-2026-47205:Authz per route crash CVE-2026-47207: ext_proc response in one gRPC message CVE-2026-47221: router internal redirects crash CVE-2026-47775: OAuth2 code verifier padding oracle CVE-2026-48044: zstd RLE zip bomb CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes CVE-2026-47692: PROXY Protocol v2 header…

E
Envoy Proxy Networking v1.39.0

v1.39.0

Summary of changes Breaking changes build: Envoy now uses Bazel 8. Because Envoy still uses WORKSPACE mode, --enable_workspace and --noenable_bzlmod are required and have been added to .bazelrc; external-repository runfiles now appear directly under the runfiles root. build: the Intel DLB connection balancer (envoy.network.connection_balance.dlb) is disabled for all builds due to a broken source a…

E
Envoy Proxy Networking v1.35.13

v1.35.13

Summary of changes: Security fixes: CVE-2026-47207: ext_proc response in one gRPC message CVE-2026-47221: router internal redirects crash CVE-2026-47775: OAuth2 code verifier padding oracle CVE-2026-48044: zstd RLE zip bomb CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causi…

E
Envoy Proxy Networking v1.37.5

v1.37.5

Summary of changes: Security fixes: CVE-2026-47205:Authz per route crash CVE-2026-47207: ext_proc response in one gRPC message CVE-2026-47221: router internal redirects crash CVE-2026-47220: REQUESTED_SERVER_NAME crash CVE-2026-47775: OAuth2 code verifier padding oracle CVE-2026-48044: zstd RLE zip bomb CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response rout…

E
Envoy Proxy Networking v1.38.3

v1.38.3

Summary of changes: Security fixes: CVE-2026-47205: Authz per route crash CVE-2026-47207: ext_proc response in one gRPC message CVE-2026-47221: router internal redirects crash CVE-2026-47220: REQUESTED_SERVER_NAME crash CVE-2026-47775: OAuth2 code verifier padding oracle CVE-2026-48044: zstd RLE zip bomb CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response rou…

E
Envoy Proxy Networking v1.36.8

v1.36.8

Summary of changes: Bug fixes: runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value. New features: http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_…

E
Envoy Proxy Networking v1.35.12

v1.35.12

Summary of changes: Bug fixes: runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value. New features: http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_…

E
Envoy Proxy Networking v1.37.4

v1.37.4

Summary of changes: Bug fixes: runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value. New features: http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_…

E
Envoy Proxy Networking v1.38.2

v1.38.2

Summary of changes: Bug fixes: runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value. New features: http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_…

E
Envoy Proxy Networking v1.37.3

v1.37.3

Summary of changes: Security fixes: CVE-2026-47774: http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards mutable_max_request_headers_kb and max_headers_count limits, protecting against an HPACK cookie-bomb that could cause excessive memory usage. This can be reverted with envoy.reloadable_features.http2_include_cookies_…

E
Envoy Proxy Networking v1.38.1

v1.38.1

Summary of changes: Security fixes: CVE-2026-47774: http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards mutable_max_request_headers_kb and max_headers_count limits, protecting against an HPACK cookie-bomb that could cause excessive memory usage. This can be reverted with envoy.reloadable_features.http2_include_cookies_…