RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jul 2026Clear ×Project: EnvoyClear ×
Envoyv1.39.0Networking & MessagingJul 14, 2026

A broad release with operator-facing changes across configuration, protocols, extensions, networking, and observability. Security fixes address multiple identified CVEs and a GHSA, while changed defaults, stricter input validation, and removed functionality may affect existing deployments.

Check if affected (11)

  • securityhighHTTP/2 header limits and flood protection

    Applies if you use HTTP/2.

    HTTP/2 counts uncompressed cookies toward header-size and header-count limits, strengthens PRIORITY and WINDOW_UPDATE flood protection, and adds configurable nghttp2 RST_STREAM rate limits in v1.39.0. The release addresses CVE-2026-47774.

  • securityhighHTTP/3 QPACK and content-length security fixes

    Applies if you use HTTP/3.

    HTTP/3 security fixes address QPACK blocked-decoding denial of service and inconsistent headers-only content-length handling in v1.39.0. The fixes address GHSA-p7c7-7c47-pwch and CVE-2026-48743.

  • securityhighAdditional protocol, parser, formatter, and decompression security fixes

    Applies if you use DNS query validation, JSON nesting limits, PROXY protocol TLV, the formatter, TCP StatsD, TLS SAN, or Zstd decompression.

    Additional security fixes for DNS query validation, JSON nesting limits, PROXY protocol TLV smuggling, formatter crashes, TCP StatsD overflow, TLS SAN NUL handling, and Zstd decompression memory exhaustion ship in v1.39.0. The fixes address CVE-2026-48497, CVE-2026-48042, CVE-2026-47692, CVE-2026-47220, CVE-2026-48706, CVE-2026-47778, and CVE-2026-48044.

  • + 8 more on the release page
Source
Browse by month