Envoy

Developer Tools

A cloud-native high-performance edge and service proxy.

Latest v1.39.0 · by CNCFWebsiteenvoyproxy/envoy

Release activity

Release activity — 10 releases across 4 days since Jun 4, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Jun 4, 2026. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026
MondayNo releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026
TuesdayNo releases on Jun 9, 2026No releases on Jun 16, 20264 releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 20261 release on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
Wednesday4 releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
Thursday1 release on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026

10 releases since Jun 4, 2026, busiest day 4

Changelog

v1.39.0

Added 6
  • New upstream RBAC and dynamic-forward-proxy resolved-address filtering provide CIDR-based protection against SSRF after DNS resolution
  • Dynamic modules gain new extension points for access-log/header formatters, downstream and upstream transport sockets, active health checkers, and stats sinks
  • Cluster load balancers can read host stats, read and write dynamic metadata and filter state, and publish main-thread state to worker-local slots
  • Dynamic modules can emit metrics from configuration and background contexts with server-wide counters tagged by extension instance
  • Wuffs-backed streaming JSON parser added for MCP, A2A, OpenAI, Anthropic, and related protocols with bounded field capture and duplicate-key detection
  • New HTTP filters provide weighted bandwidth sharing and selectable sub-filter chains with per-route configuration
Changed 3
  • Envoy now uses Bazel 8, requiring --enable_workspace and --noenable_bzlmod flags in .bazelrc
  • TLS inspector validates client TLS versions to be between TLS 1.0 and TLS 1.3
  • OpenTelemetry tracer now honors Envoy's request-entry sampling decision including overall_sampling, which may reduce exported spans
Removed 1
  • Intel DLB connection balancer (envoy.network.connection_balance.dlb) is disabled for all builds due to a broken source archive
Deprecated 1
  • enforce_rsa_key_usage is deprecated and ignored; Envoy now always enforces the certificate keyUsage extension
Security 7
  • HTTP/2 now counts uncompressed cookies toward header-size and header-count limits (CVE-2026-47774) and strengthens PRIORITY/WINDOW_UPDATE flood protection
  • HTTP/2 adds configurable nghttp2 RST_STREAM rate limits
  • HTTP/3 fixes QPACK blocked-decoding denial of service (GHSA-p7c7-7c47-pwch)
  • HTTP/3 fixes inconsistent headers-only content-length handling (CVE-2026-48743)
  • Added security fixes for ext_authz (CVE-2026-47205), ext_proc (CVE-2026-47207), gRPC stats (CVE-2026-47204), internal redirects (CVE-2026-47221), and OAuth2 lifecycle handling (CVE-2026-48090)
  • OAuth2 adds AES-256-GCM cookie encryption to address CVE-2026-47775 with opt-in migration via oauth2_use_gcm_encryption flag
  • Fixed DNS query validation (CVE-2026-48497), JSON nesting limits (CVE-2026-48042), PROXY protocol TLV smuggling (CVE-2026-47692), formatter crashes (CVE-2026-47220), TCP StatsD overflow (CVE-2026-48706), TLS SAN NUL handling (CVE-2026-47778), and Zstd decompression memory exhaustion (CVE-2026-48044)
Summary of changes
Breaking changes
  • build: Envoy now uses Bazel 8. Because Envoy still uses WORKSPACE mode, --enable_workspace and --noenable_bzlmod are required and have been added to .bazelrc; external-repository runfiles now appear directly under the runfiles root.
  • build: the Intel DLB connection balancer (envoy.network.connection_balance.dlb) is disabled for all builds due to a broken source archive.
  • TLS: enforce_rsa_key_usage is deprecated and ignored; Envoy now always enforces the certificate keyUsage extension.
  • TLS inspector: client TLS versions are validated and must be between TLS 1.0 and TLS 1.3 (revertible via envoy.reloadable_features.tls_inspector_enforce_client_tls_version).
  • OpenTelemetry tracing: the tracer now honors Envoy's request-entry sampling decision, including overall_sampling, even when propagated trace context or the configured sampler requests sampling. This may reduce exported spans.
Security
  • HTTP/2 now counts uncompressed cookies toward header-size and header-count limits (CVE-2026-47774), strengthens PRIORITY/WINDOW_UPDATE flood protection, and adds configurable nghttp2 RST_STREAM rate limits.
  • HTTP/3 fixes cover QPACK blocked-decoding denial of service (GHSA-p7c7-7c47-pwch) and inconsistent headers-only content-length handling (CVE-2026-48743).
  • Security fixes were added for ext_authz (CVE-2026-47205), ext_proc (CVE-2026-47207), gRPC stats (CVE-2026-47204), internal redirects (CVE-2026-47221), and OAuth2 lifecycle handling (CVE-2026-48090).
  • OAuth2 adds AES-256-GCM cookie encryption to address CVE-2026-47775. Migration is opt-in: enable oauth2_use_gcm_encryption, monitor oauth_legacy_cbc_decrypt, then disable oauth2_legacy_cbc_decrypt_compat.
  • Additional fixes cover DNS query validation (CVE-2026-48497), JSON nesting limits (CVE-2026-48042), PROXY protocol TLV smuggling (CVE-2026-47692), formatter crashes (CVE-2026-47220), TCP StatsD overflow (CVE-2026-48706), TLS SAN NUL handling (CVE-2026-47778), and Zstd decompression memory exhaustion (CVE-2026-48044).
  • New upstream RBAC and dynamic-forward-proxy resolved-address filtering provide CIDR-based protection against SSRF after DNS resolution and host selection.
Dynamic modules
  • New extension points: access-log/header formatters, downstream and upstream transport sockets, active health checkers, and stats sinks.
  • Cluster load balancers can read host stats, read and write dynamic metadata and filter state, and publish main-thread state to worker-local slots.
  • Modules can emit metrics from configuration and background contexts; loading and initialization failures now expose server-wide counters tagged by extension instance.
  • Added validation-mode detection, network/listener attribute access, batched header and metadata APIs, effective log-level access, and zero-copy borrowed buffers in the Rust SDK.
  • Fixed listener HTTP-callout crashes, watermark initialization, streaming-response re-entry, independent decode/encode continuation, CatchUnwind re-entry, Struct configuration handling, and HTTP/TCP bridge buffer overflow with more than 64 slices.
MCP (Model Context Protocol) and AI protocols
  • Added a Wuffs-backed streaming JSON parser for MCP, A2A, OpenAI, Anthropic, and related protocols, with bounded field capture, incremental parsing, no DOM allocation, and duplicate-key detection.
  • MCP filtering now exposes processing status, supports configurable duplicate-key rejection, and improves oversized-body behavior for pass-through and rejection modes.
  • MCP router adds elicitation and server-to-client request routing, plus lazy per-backend initialization.
  • MCP JSON REST Bridge adds per-route tool configuration and locally generated tools/list responses.
HTTP, routing and protocol
  • New HTTP filters provide weighted bandwidth sharing and selectable sub-filter chains with per-route configuration.
  • HeaderMatcher now evaluates separately supplied header values individually instead of matching only their comma-joined representation (revertible via envoy.reloadable_features.match_headers_individually).
  • HTTP inspector uses Balsa by default and now fast-fails invalid non-HTTP method bytes instead of buffering up to 64 KiB.
  • Added drain-timeout and maximum-connection-duration jitter to reduce synchronized reconnect spikes.
  • Routing gains cluster refresh on retries, weighted-cluster reselection, formatter/CEL-based redirect paths, and mixed literal/variable URI-template segments.
  • Fixed connection-pool re-entrancy, connectivity-grid teardown and duplicate-attempt bugs, stale on-demand cluster information, and handling of HTTP/2 or HTTP/3 RST_STREAM(NO_ERROR) after complete responses.
TLS, authentication and authorization
  • Added CNSA 1.0/2.0 compliance policies, TLS group formatters for identifying post-quantum key exchange, and suppression of oversized client CA lists.
  • QUIC supports opt-in TLS key logging and session-ticket resumption.
  • TLS certificate compression via the brotli runtime guard is disabled by default; TLS sockets also gain improved connection-reset reporting.
  • OAuth2 adds PRIVATE_KEY_JWT, ID-token forwarding, configurable post-logout redirects, access-token-based cookie lifetime, and safe original-request URI formatting with redirect-domain allowlists.
  • BasicAuth supports missing-credential pass-through and authenticated-username metadata; JWT extraction can mark forwarded claims whose signatures were not verified.
DNS, load balancing and upstream
  • The unified DNS cluster implementation is enabled by default; equivalent c-ares resolvers can be shared across clusters to support shared qcache.
  • DNS clusters gain a minimum TTL refresh floor, while dynamic forward proxy sub-clusters can use DnsCluster configuration and resolved-address CIDR filtering.
  • Client-side weighted round robin adds out-of-band ORCA reporting with configurable port, authority, and transport socket matching.
  • Least-request load balancing can optionally account for pending requests, with a new per-endpoint pending-request gauge.
  • Fixed EDS hostname updates, load reports containing only custom metrics or completed requests, and dynamic-forward-proxy lookup teardown.
Networking and system performance
  • Linux deployments gain worker CPU affinity and an SO_REUSEPORT BPF connection balancer for CPU-local connection steering.
  • Added a Linux sockmap socket interface for accelerating same-host TCP traffic through eBPF.
  • io_uring adds multishot receives, adaptive read buffers, and configurable write backpressure.
  • Reverse tunnels gain opt-in GOAWAY-aware draining and replacement; MySQL proxy adds downstream TLS termination with caching_sha2_password mediation.
  • Added UDP proxy external authorization, network ext_proc metadata reception, and early external-processor stream closure.
Observability
  • New access-log data includes upstream TLS SNI and HTTP/TCP downstream/upstream connection duration points; gRPC access logging adds delivery success/failure counters.
  • Added dynamic-module and Wasm programmable stats sinks, OpenTelemetry metric request chunking, endpoint observability names, and default-tag overrides.
  • Prometheus scraping and large-scale stat-reference release are substantially faster; /peak_heap_dump exposes tcmalloc's peak heap profile.
  • Added process-wide Lua and Wasm VM gauges, single-entry stack traces, and an Envoy-version log-format token.
  • Tap now honors configured runtime sampling and reports sampled-out requests/connections.
Rate limiting and configuration
  • Rate limiting adds static and dynamic per-descriptor limit overrides, zero-token always-reject behavior, and configurable response-metadata namespaces.
  • GCP authentication supports bound access tokens, bound JWTs, and unbound access tokens from the metadata server.
  • Added file-backed IP tagging, in-place watched-file modification events, runtime-adjustable fixed-heap limits, health-check HTTP status events, and xDS unsubscribe callbacks.
  • Redis proxy adds Redis 7.4 hash-field expiry commands and permits custom commands inside transactions.
Other notable changes and fixes
  • Fixed Hickory DNS resolver leaks and use-after-free, file-server cancellation use-after-free, Golang filter re-entry, outlier-detection teardown, missing network namespaces, and asynchronous TLS close handling.
  • Fixed RTDS guard removal, VHDS subscriptions, Wasm VM cache invalidation when environment variables change, and upstream Wasm metric scoping.
  • Improved UDP proxy attempted-host and address logging, Zipkin timestamp trace IDs, gRPC access-log failure accounting, and health-check event detail.
  • Added TCP proxy delayed route selection, drain-close handling, and connection-duration access logging.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.0 Docs: https://www.envoyproxy.io/docs/envoy/v1.39.0/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.39.0/version_history/v1.39/v1.39.0 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.38.0...v1.39.0

Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com Signed-off-by: Ryan Northey ryan@synca.io Signed-off-by: Jonh Wendell jwendell@redhat.com

View originalPermalink
How v1.39.0 went

v1.38.3

Changed 1
  • Disabled runtime guard envoy.reloadable_features.tls_certificate_compression_brotli by default, retaining zlib-only certificate compression for QUIC and disabling certificate compression for TCP TLS
Removed 1
  • Disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms
Security 16
  • Fixed authz per route crash
  • Fixed ext_proc response in one gRPC message
  • Fixed router internal redirects crash
  • Fixed REQUESTED_SERVER_NAME crash
  • Fixed OAuth2 code verifier padding oracle
  • Fixed zstd RLE zip bomb

Summary of changes:

  • Security fixes:

    • CVE-2026-47205: Authz per route crash
    • CVE-2026-47207: ext_proc response in one gRPC message
    • CVE-2026-47221: router internal redirects crash
    • CVE-2026-47220: REQUESTED_SERVER_NAME crash
    • CVE-2026-47775: OAuth2 code verifier padding oracle
    • CVE-2026-48044: zstd RLE zip bomb
    • CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
    • CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
    • CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
    • CVE-2026-48042: Stack overflow in destructor of highly nested JSON
    • CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
    • CVE-2026-48497: Abnormal process termination in DNS UDP filter
    • CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
    • CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
    • GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
  • Upstream security fixes:

    • CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.
  • Behavior changes:

    • build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See https://github.com/envoyproxy/envoy/issues/45491 for local workarounds.
  • Minor behavior changes:

    • tls: runtime guard envoy.reloadable_features.tls_certificate_compression_brotli is now disabled by default. When disabled, QUIC retains zlib-only certificate compression and TCP TLS performs no certificate compression. It can be re-enabled by setting the runtime guard to true.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.3 Docs: https://www.envoyproxy.io/docs/envoy/v1.38.3/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.38.3/version_history/v1.38/v1.38.3 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.38.2...v1.38.3

Signed-off-by: Greg Greenway ggreenway@apple.com Signed-off-by: Jonh Wendell jonh.wendell@redhat.com Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com Signed-off-by: Ryan Northey ryan@synca.io Signed-off-by: Boteng Yao boteng@google.com

View originalPermalink
How v1.38.3 went

v1.37.5

Changed 1
  • Disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms
Security 16
  • Fixed authz per route crash
  • Fixed ext_proc response in one gRPC message
  • Fixed router internal redirects crash
  • Fixed REQUESTED_SERVER_NAME crash
  • Fixed OAuth2 code verifier padding oracle
  • Fixed zstd RLE zip bomb

Summary of changes:

  • Security fixes:

    • CVE-2026-47205:Authz per route crash
    • CVE-2026-47207: ext_proc response in one gRPC message
    • CVE-2026-47221: router internal redirects crash
    • CVE-2026-47220: REQUESTED_SERVER_NAME crash
    • CVE-2026-47775: OAuth2 code verifier padding oracle
    • CVE-2026-48044: zstd RLE zip bomb
    • CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
    • CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
    • CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
    • CVE-2026-48042: Stack overflow in destructor of highly nested JSON
    • CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
    • CVE-2026-48497: Abnormal process termination in DNS UDP filter
    • CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
    • CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
    • GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
  • Upstream security fixes:

    • CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.
  • Behavior changes:

    • build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See https://github.com/envoyproxy/envoy/issues/45491 for local workarounds.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.5 Docs: https://www.envoyproxy.io/docs/envoy/v1.37.5/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.37.5/version_history/v1.37/v1.37.5 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.37.4...v1.37.5

Signed-off-by: Greg Greenway ggreenway@apple.com Signed-off-by: Jonh Wendell jonh.wendell@redhat.com Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com Signed-off-by: Ryan Northey ryan@synca.io Signed-off-by: Boteng Yao boteng@google.com

View originalPermalink
How v1.37.5 went

v1.36.9

Changed 1
  • Disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to breakage at the source archive
Security 15
  • Fixed CVE-2026-47205: authz per route crash
  • Fixed CVE-2026-47207: ext_proc response in one gRPC message
  • Fixed CVE-2026-47221: router internal redirects crash
  • Fixed CVE-2026-47775: OAuth2 code verifier padding oracle
  • Fixed CVE-2026-48044: zstd RLE zip bomb
  • Fixed CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes

Summary of changes:

  • Upstream security fixes:

    • CVE-2026-47205:Authz per route crash
    • CVE-2026-47207: ext_proc response in one gRPC message
    • CVE-2026-47221: router internal redirects crash
    • CVE-2026-47775: OAuth2 code verifier padding oracle
    • CVE-2026-48044: zstd RLE zip bomb
    • CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
    • CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
    • CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
    • CVE-2026-48042: Stack overflow in destructor of highly nested JSON
    • CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
    • CVE-2026-48497: Abnormal process termination in DNS UDP filter
    • CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
    • CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
    • GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
  • Upstream security fixes:

    • CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.
  • Behavior changes:

    • build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See https://github.com/envoyproxy/envoy/issues/45491 for local workarounds.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.9 Docs: https://www.envoyproxy.io/docs/envoy/v1.36.9/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.36.9/version_history/v1.36/v1.36.9 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.36.8...v1.36.9

Signed-off-by: Greg Greenway ggreenway@apple.com Signed-off-by: Jonh Wendell jonh.wendell@redhat.com Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com Signed-off-by: Ryan Northey ryan@synca.io Signed-off-by: Boteng Yao boteng@google.com

View originalPermalink
How v1.36.9 went

v1.35.13

Changed 1
  • Disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to source archive breakage
Security 14
  • Fixed ext_proc response handling in single gRPC message
  • Fixed router internal redirects crash
  • Fixed OAuth2 code verifier padding oracle vulnerability
  • Fixed zstd RLE zip bomb vulnerability
  • Fixed grpc_stats filter segfault on Connect protocol requests to direct_response routes
  • Fixed PROXY Protocol v2 header generator emitting skipped TLVs causing upstream application stream spillover

Summary of changes:

  • Security fixes:

    • CVE-2026-47207: ext_proc response in one gRPC message
    • CVE-2026-47221: router internal redirects crash
    • CVE-2026-47775: OAuth2 code verifier padding oracle
    • CVE-2026-48044: zstd RLE zip bomb
    • CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
    • CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
    • CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
    • CVE-2026-48042: Stack overflow in destructor of highly nested JSON
    • CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
    • CVE-2026-48497: DNS filter abnormal process termination on long query name
    • CVE-2026-48743: HTTP/3 headers-only request/response content-length not validated
    • CVE-2026-48706: TcpStatsdSync buffer overflow with large stats name
    • GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
  • Upstream security fixes:

    • CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.
  • Behavior changes:

    • build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See https://github.com/envoyproxy/envoy/issues/45491 for local workarounds.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.13 Docs: https://www.envoyproxy.io/docs/envoy/v1.35.13/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.35.13/version_history/v1.35/v1.35.13 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.35.12...v1.35.13

Signed-off-by: Greg Greenway ggreenway@apple.com Signed-off-by: Jonh Wendell jonh.wendell@redhat.com Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com Signed-off-by: Ryan Northey ryan@synca.io Signed-off-by: Boteng Yao boteng@google.com

View originalPermalink
How v1.35.13 went

v1.38.2

Added 2
  • Added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count, enabled with envoy.reloadable_features.http2_record_histograms
  • Added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header
Fixed 1
  • Fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value

Summary of changes:

  • Bug fixes:

    • runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
  • New features:

    • http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
    • http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.2 Docs: https://www.envoyproxy.io/docs/envoy/v1.38.2/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.38.2/version_history/v1.38/v1.38.2 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.38.1...v1.38.2

Signed-off-by: Ryan Northey ryan@synca.io Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

View originalPermalink
How v1.38.2 went

v1.37.4

Added 2
  • Added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count, enabled with envoy.reloadable_features.http2_record_histograms
  • Added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header
Fixed 1
  • Fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value

Summary of changes:

  • Bug fixes:

    • runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
  • New features:

    • http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
    • http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.4 Docs: https://www.envoyproxy.io/docs/envoy/v1.37.4/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.37.4/version_history/v1.37/v1.37.4 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.37.3...v1.37.4

Signed-off-by: Ryan Northey ryan@synca.io Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

View originalPermalink
How v1.37.4 went

v1.36.8

Added 2
  • Added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count, enabled with envoy.reloadable_features.http2_record_histograms
  • Added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header
Fixed 1
  • Fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value

Summary of changes:

  • Bug fixes:

    • runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
  • New features:

    • http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
    • http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.8 Docs: https://www.envoyproxy.io/docs/envoy/v1.36.8/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.36.8/version_history/v1.36/v1.36.8 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.36.7...v1.36.8

Signed-off-by: Ryan Northey ryan@synca.io Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

View originalPermalink
How v1.36.8 went

v1.35.12

Added 2
  • Added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count, enabled with envoy.reloadable_features.http2_record_histograms
  • Added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header
Fixed 1
  • Fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value

Summary of changes:

  • Bug fixes:

    • runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
  • New features:

    • http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
    • http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.12 Docs: https://www.envoyproxy.io/docs/envoy/v1.35.12/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.35.12/version_history/v1.35/v1.35.12 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.35.11...v1.35.12

Signed-off-by: Ryan Northey ryan@synca.io Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

View originalPermalink
How v1.35.12 went

v1.38.1

Changed 2
  • The upstream transport failure reason is no longer included in the HTTP response body sent to downstream clients, but remains available in access logs
  • Load balancer rebuild coalescing during EDS batch host updates is now opt-in
Fixed 1
  • Fixed a crash in the HTTP filter when a stream was already above the downstream write-buffer high watermark at filter-chain construction time
Security 4
  • HTTP/2 streams are now reset if they violate the configured maximum header list size, and uncompressed cookies now count towards mutable_max_request_headers_kb and max_headers_count limits to protect against HPACK cookie-bomb attacks
  • Fixed a timing side-channel in oauth2 HMAC verification that could leak HMAC secret validity
  • Fixed a crash in oauth2 where AES-CBC decryption of token cookies could spuriously succeed on a secret mismatch, tripping a HeaderString validation assert
  • Applied nghttp2 CVE-2026-27135 patch for HTTP/2

Summary of changes:

  • Security fixes:

    • CVE-2026-47774: http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards mutable_max_request_headers_kb and max_headers_count limits, protecting against an HPACK cookie-bomb that could cause excessive memory usage. This can be reverted with envoy.reloadable_features.http2_include_cookies_in_limits.
    • oauth2: fixed a timing side-channel in HMAC verification that could leak HMAC secret validity.
    • oauth2: fixed a crash where AES-CBC decryption of token cookies could spuriously succeed (~1/256) on a secret mismatch, tripping a HeaderString validation assert.
    • CVE-2026-27135: http2: applied nghttp2 CVE-2026-27135 patch.
  • Bug fixes:

    • dynamic_modules: fixed a crash in the HTTP filter when a stream was already above the downstream write-buffer high watermark at filter-chain construction time.
  • Minor behavior changes:

    • router: the upstream transport failure reason is no longer included in the HTTP response body sent to downstream clients (still available in access logs via %UPSTREAM_TRANSPORT_FAILURE_REASON%). Revert with envoy.reloadable_features.hide_transport_failure_reason_in_response_body.
    • upstream: load balancer rebuild coalescing during EDS batch host updates is now opt-in. Re-enable with envoy.reloadable_features.coalesce_lb_rebuilds_on_batch_update.

Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.1 Docs: https://www.envoyproxy.io/docs/envoy/v1.38.1/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.38.1/version_history/v1.38/v1.38.1 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.38.0...v1.38.1

Signed-off-by: Jonh Wendell jonh.wendell@redhat.com Signed-off-by: Greg Greenway ggreenway@apple.com Signed-off-by: Ryan Northey ryan@synca.io

View originalPermalink
How v1.38.1 went
View all

Discussion