RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: EnvoyClear ×
Envoyv1.38.2Networking & MessagingJun 10, 2026

This maintenance release adds HTTP/2 runtime controls and corrects runtime guard override handling. It also announces future removal of the HTTP/2 histogram feature and its runtime guard.

Plan ahead (1)

  • deprecatedFuture removal of envoy.reloadable_features.http2_record_histogramsremoval date not announced

    Applies if envoy.reloadable_features.http2_record_histograms is enabled.

    The HTTP/2 histograms and runtime guard controlled by envoy.reloadable_features.http2_record_histograms will be removed in a future Envoy release.

Source
Envoyv1.37.4Networking & MessagingJun 10, 2026

This release adds HTTP/2 header-statistics histograms and a cookie-size limit, and fixes RTDS runtime guard override removal. The HTTP/2 histogram runtime guard is planned for removal in a future Envoy release.

Plan ahead (1)

  • deprecatedThe envoy.reloadable_features.http2_record_histograms histograms and runtime guard, planned for future removalremoval date not announced

    Applies if you use envoy.reloadable_features.http2_record_histograms.

    The HTTP/2 histograms and runtime guard for envoy.reloadable_features.http2_record_histograms will be removed in a future Envoy release.

Source
Envoyv1.36.8Networking & MessagingJun 10, 2026

A maintenance release corrects RTDS runtime-guard override behavior and adds opt-in HTTP/2 cookie and header capabilities. The existing HTTP/2 histogram capability and its runtime guard are announced for future removal.

Plan ahead (1)

  • deprecatedenvoy.reloadable_features.http2_record_histograms, future removalremoval date not announced

    Applies if you use envoy.reloadable_features.http2_record_histograms.

    The histograms and runtime guard controlled by envoy.reloadable_features.http2_record_histograms will be removed in a future Envoy release.

Source
Envoyv1.38.0Networking & MessagingApr 23, 2026

A release with breaking configuration and flag changes, many new extension and protocol capabilities, and fixes for security, correctness, and observability. The recorded additions include module and filter extension APIs, MCP and A2A protocol support, OpenSSL builds, new formatters and metrics, and expanded streaming and TLS capabilities.

Action needed (1)

  • securityhighnghttp2 **CVE-2026-27135** patch

    The nghttp2 **CVE-2026-27135** patch is included.

Check if affected (6)

  • securityURL encoding for query_parameter_mutations values

    Applies if you configure query_parameter_mutations.

    Query-parameter values added through query_parameter_mutations are now URL-encoded to prevent injection.

  • securityRBAC concatenation-based bypass prevention

    Applies if RBAC runs.

    RBAC handling was corrected to prevent concatenation-based bypasses.

  • breakingExplicit max_early_data_bytes configuration

    Applies if you configure upstream_connect_mode with a value other than IMMEDIATE and do not configure max_early_data_bytes.

    max_early_data_bytes must now be set explicitly when upstream_connect_mode has a value other than IMMEDIATE. Missing configuration causes validation to fail at startup.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedThe enforce_rsa_key_usage option, deprecatedremoval date not announced

    Applies if you configure enforce_rsa_key_usage.

    The enforce_rsa_key_usage option is deprecated and will be removed in the next release.

Source
Envoyv1.37.0Networking & MessagingJan 13, 2026

This release adds dynamic-module, filter, routing, observability, and certificate capabilities, along with fixes and performance improvements across HTTP, networking, and protocol handling. It also changes HTTP reset behavior, removes runtime guards and legacy code paths, and deprecates the OpenTelemetry access log common_config field.

Action needed (1)

  • breakingRuntime guards and legacy code paths removed

    Multiple runtime guards and legacy code paths are removed in this release.

Check if affected (2)

  • breakingDefault HTTP reset code changed

    Applicability is not stated in the release notes.

    The default HTTP reset code changes from NO_ERROR to INTERNAL_ERROR.

  • breakingDefault upstream protocol error reset handling changed

    Applicability is not stated in the release notes.

    Reset handling now ignores upstream protocol errors by default.

Plan ahead (1)

  • deprecatedOpenTelemetry access log common_config field deprecated

    Applies if you configure common_config.

    The OpenTelemetry access log common_config field is deprecated in favor of explicit http_service or grpc_service configuration.

Source
Browse by month