v1.36.10
Summary of changes: Security fixes: CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with envoy.reloadable_features.strip_path_parameters_per_segment. CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames. CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag…