E

Envoy Proxy

E
Envoy Proxy Networking v1.39.0

v1.39.0

Summary of changes Breaking changes build: Envoy now uses Bazel 8. Because Envoy still uses WORKSPACE mode, --enable_workspace and --noenable_bzlmod are required and have been added to .bazelrc; external-repository runfiles now appear directly under the runfiles root. build: the Intel DLB connection balancer (envoy.network.connection_balance.dlb) is disabled for all builds due to a broken source a…

E
Envoy Proxy Networking v1.35.13

v1.35.13

Summary of changes: Security fixes: CVE-2026-47207: ext_proc response in one gRPC message CVE-2026-47221: router internal redirects crash CVE-2026-47775: OAuth2 code verifier padding oracle CVE-2026-48044: zstd RLE zip bomb CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causi…

E
Envoy Proxy Networking v1.36.9

v1.36.9

Summary of changes: Upstream security fixes: CVE-2026-47205:Authz per route crash CVE-2026-47207: ext_proc response in one gRPC message CVE-2026-47221: router internal redirects crash CVE-2026-47775: OAuth2 code verifier padding oracle CVE-2026-48044: zstd RLE zip bomb CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes CVE-2026-47692: PROXY Protocol v…

E
Envoy Proxy Networking v1.37.5

v1.37.5

Summary of changes: Security fixes: CVE-2026-47205:Authz per route crash CVE-2026-47207: ext_proc response in one gRPC message CVE-2026-47221: router internal redirects crash CVE-2026-47220: REQUESTED_SERVER_NAME crash CVE-2026-47775: OAuth2 code verifier padding oracle CVE-2026-48044: zstd RLE zip bomb CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response rout…

E
Envoy Proxy Networking v1.38.3

v1.38.3

Summary of changes: Security fixes: CVE-2026-47205: Authz per route crash CVE-2026-47207: ext_proc response in one gRPC message CVE-2026-47221: router internal redirects crash CVE-2026-47220: REQUESTED_SERVER_NAME crash CVE-2026-47775: OAuth2 code verifier padding oracle CVE-2026-48044: zstd RLE zip bomb CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response rou…

E
Envoy Proxy Networking v1.36.8

v1.36.8

Summary of changes: Bug fixes: runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value. New features: http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_…

E
Envoy Proxy Networking v1.35.12

v1.35.12

Summary of changes: Bug fixes: runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value. New features: http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_…

E
Envoy Proxy Networking v1.37.4

v1.37.4

Summary of changes: Bug fixes: runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value. New features: http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_…

E
Envoy Proxy Networking v1.38.2

v1.38.2

Summary of changes: Bug fixes: runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value. New features: http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_…

E
Envoy Proxy Networking v1.37.3

v1.37.3

Summary of changes: Security fixes: CVE-2026-47774: http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards mutable_max_request_headers_kb and max_headers_count limits, protecting against an HPACK cookie-bomb that could cause excessive memory usage. This can be reverted with envoy.reloadable_features.http2_include_cookies_…

E
Envoy Proxy Networking v1.38.1

v1.38.1

Summary of changes: Security fixes: CVE-2026-47774: http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards mutable_max_request_headers_kb and max_headers_count limits, protecting against an HPACK cookie-bomb that could cause excessive memory usage. This can be reverted with envoy.reloadable_features.http2_include_cookies_…