A security-focused maintenance release with fixes across filters, protocol handling, request processing, and JSON parsing. It also updates the Wasmtime dependency and disables the contrib extension envoy..
Action needed (1)
securityhighHighly nested JSON destructor stack overflow, corrected for CVE-2026-48042
This release corrects the stack overflow in the destructor of highly nested JSON described by CVE-2026-48042 and GHSA-f24p-rxw2-g6pv.
Check if affected (14)
securityhighzstd RLE zip bomb, corrected for CVE-2026-48044
Applies if you use
zstd.securityhighHTTP/3 headers-only content-length validation, corrected for CVE-2026-48743
Applies if you use
HTTP/3.securityhigh
com_github_wasmtimedependency update for CVE-2026-47261Applies if you use
wasm.- + 11 more on the release page