A maintenance release with multiple Envoy and Istio security fixes covering request handling, authorization, authentication, and plugin image fetching. It also includes ordinary correctness fixes and adds configuration for authorized namespaces on debug endpoints.
Action needed (1)
securitymediumCVE-2026-26309 JSON off-by-one write fix
CVE-2026-26309 fixes an off-by-one write in JSON handling.
Check if affected (10)
securityhighCVE-2026-26308 multivalue header bypass fix
Applies if you use
RBAC.CVE-2026-26308 fixes a multivalue header bypass in
RBAC.securityhighCVE-2026-31837 and GHSA-v75c-crr9-733c JWKS resolver authentication fix
Applies if you use
JWKS Resolver.CVE-2026-31837 and GHSA-v75c-crr9-733c fix the
JWKS Resolverfailure that could allow authentication bypass using known default keys.securitymediumCVE-2026-26311 HTTP decode method restriction
Applies if you use
HTTP.CVE-2026-26311 blocks HTTP decode methods after a downstream reset.
- + 7 more on the release page