A broad release with operator-facing changes across configuration, protocols, extensions, networking, and observability. Security fixes address multiple identified CVEs and a GHSA, while changed defaults, stricter input validation, and removed functionality may affect existing deployments.
Check if affected (11)
securityhigh
HTTP/2header limits and flood protectionApplies if you use
HTTP/2.HTTP/2counts uncompressed cookies toward header-size and header-count limits, strengthensPRIORITYandWINDOW_UPDATEflood protection, and adds configurable nghttp2RST_STREAMrate limits in v1.39.0. The release addresses CVE-2026-47774.securityhigh
HTTP/3QPACK andcontent-lengthsecurity fixesApplies if you use
HTTP/3.HTTP/3security fixes address QPACK blocked-decoding denial of service and inconsistent headers-onlycontent-lengthhandling in v1.39.0. The fixes address GHSA-p7c7-7c47-pwch and CVE-2026-48743.securityhighAdditional protocol, parser, formatter, and decompression security fixes
Applies if you use DNS query validation, JSON nesting limits, PROXY protocol TLV, the formatter, TCP StatsD, TLS SAN, or Zstd decompression.
Additional security fixes for DNS query validation, JSON nesting limits, PROXY protocol TLV smuggling, formatter crashes, TCP StatsD overflow, TLS SAN NUL handling, and Zstd decompression memory exhaustion ship in v1.39.0. The fixes address CVE-2026-48497, CVE-2026-48042, CVE-2026-47692, CVE-2026-47220, CVE-2026-48706, CVE-2026-47778, and CVE-2026-48044.
- + 8 more on the release page