A maintenance release with a changed logging default, operator-facing additions and fixes, and a restriction on pilot-agent metric content types. It also includes Envoy security fixes covering denial-of-service, crashes, validation issues, memory exhaustion, and other vulnerabilities.
Action needed (12)
securityhighCVE-2026-47220 crash bug fix
The Envoy security update fixes the crash bug described by CVE-2026-47220.
securityhighCVE-2026-48044 memory exhaustion fix
The Envoy security update fixes the memory exhaustion vulnerability described by CVE-2026-48044.
securityhighCVE-2026-48042 JSON nesting-depth limit
The Envoy security update limits JSON nesting depth to 1000 through
envoy..reloadable_features. limit_json_parser_nesting_depth securitymediumCVE-2026-47692 bug fix
The Envoy security update fixes the bug described by CVE-2026-47692.
securitymediumCVE-2026-47205 use-after-free crash fix
The Envoy security update fixes the use-after-free crash described by CVE-2026-47205.
securitymediumCVE-2026-48090 asynchronous token callback handling
The Envoy security update fixes a bug where the asynchronous token change callback could be triggered after the filter had been torn down.
securitymediumCVE-2026-47778 Subject Alternative Name validation
The Envoy security update fixes an issue where Envoy could fail to validate the Subject Alternative Name (SAN).
securitymediumCVE-2026-47204 crash and use-after-free fix
The Envoy security update fixes a crash or use-after-free described by CVE-2026-47204.
securitymediumCVE-2026-48497 query name length checking
The Envoy security update fixes sanity checking of the query name length.
securitymediumCVE-2026-47775 padding oracle
The Envoy security update addresses a padding oracle described by CVE-2026-47775.
securityGHSA-p7c7-7c47-pwch denial-of-service fix
The Envoy security update fixes the denial-of-service vulnerability described by GHSA-p7c7-7c47-pwch.
breakingWarn-level message logging
The message is now logged at
warnlevel.
Check if affected (5)
securityhighCVE-2026-48743 HTTP/3 content-length validation
Applies if you use HTTP/3.
The Envoy security update fixes HTTP/3 headers-only request and response content-length validation, including the
envoy.feature.reloadable_features. quic_validate_headers_only_content_length securitymediumCVE-2026-47207
ext_procresponse handlingApplies if you use the
ext_procextension.The Envoy security update fixes a bug where the
ext_procserver sends unexpectedProcessingResponsesto Envoy.securitymediumCVE-2026-47221 HTTP 303 redirect handling
Applicability is not stated in the release notes.
The Envoy security update fixes an issue when handling HTTP 303 internal redirects.
- + 2 more on the release page