v0.55.8

Try our Chrome extension

Chrome store icon Chrome Webstore

Easily add the current web-page from your browser directly into your changedetection.io tool, more great features coming soon!

Changedetection.io needs your support!

You can help us by supporting changedetection.io on these platforms;

The more popular changedetection.io is, the more time we can dedicate to adding amazing features!

Many thanks :)

changedetection.io team

  • Cannot set language without session cookie
  • Historie pro vybraný odkaz nenalezena, chybný odkaz?
  • Smazáno

Klávesnice: ← Předchozí   → Další
Ještě ne před sekundami
            False
        
Ještě ne před sekundami
Aktuální chybový snímek obrazovky z posledního požadavku

Spouštěcí text Ignorovaný text Blokovaný text

15 hours ago
    Skip to content

      Navigation Menu

            Sign in Appearance settings
                * Platform
                        + AI CODE CREATION
                            o GitHub Copilot Write better code with AI
                            o GitHub Copilot app Direct agents from issue to merge
                            o MCP Registry Integrate external tools
                        + DEVELOPER WORKFLOWS
                            o Actions Automate any workflow
                            o Codespaces Instant dev environments
                            o Issues Plan and track work
                            o Code Review Manage code changes
                            o Code Quality Enforce quality at merge
                        + APPLICATION SECURITY
                            o GitHub Advanced Security Find and fix vulnerabilities
                            o Code security Secure your code as you build
                            o Secret protection Stop leaks before they start
                        + EXPLORE
                            o Why GitHub
                            o Documentation
                            o Blog
                            o Changelog
                            o Marketplace
                      View all features
                * Solutions
                        + BY COMPANY SIZE
                            o Enterprises
                            o Small and medium teams
                            o Startups
                            o Nonprofits
                        + BY USE CASE
                            o App Modernization
                            o DevSecOps
                            o DevOps
                            o CI/CD
                            o View all use cases
                        + BY INDUSTRY
                            o Healthcare
                            o Financial services
                            o Manufacturing
                            o Government
                            o View all industries
                      View all solutions
                * Resources
                        + EXPLORE BY TOPIC
                            o AI
                            o Software Development
                            o DevOps
                            o Security
                            o View all topics
                        + EXPLORE BY TYPE
                            o Customer stories
                            o Events & webinars
                            o Ebooks & reports
                            o Business insights
                            o GitHub Skills
                        + SUPPORT & SERVICES
                            o Documentation
                            o Customer support
                            o Community forum
                            o Trust center
                            o Partners
                      View all resources
                * Open Source
                        + COMMUNITY
                            o GitHub Sponsors Fund open source developers
                        + PROGRAMS
                            o Security Lab
                            o Maintainer Community
                            o Accelerator
                            o GitHub Stars
                            o Archive Program
                        + REPOSITORIES
                            o Topics
                            o Trending
                            o Collections
                * Enterprise
                        + ENTERPRISE SOLUTIONS
                            o Enterprise platform AI-powered developer platform
                        + AVAILABLE ADD-ONS
                            o GitHub Advanced Security Enterprise-grade security features
                            o Copilot for Business Enterprise-grade AI features
                            o Premium Support Enterprise-grade 24/7 support
              * Pricing
                Type / to search
                Sign in
              Sign up Appearance settings
      You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert

              Uh oh!

              There was an error while loading. Please reload this page.

              envoyproxy / envoy Public
              * Notifications You must be signed in to change notification settings
              * Fork 5.5k
                * Star 28.7k
          * Code
          * Issues 1.6k
          * Pull requests 204
          * Discussions
          * Actions
          * Projects
          * Wiki
          * Security and quality 117
          * Insights
          Additional navigation options
                  * Code
                  * Issues
                  * Pull requests
                  * Discussions
                  * Actions
                  * Projects
                  * Wiki
                  * Security and quality
                  * Insights

        Releases: envoyproxy/envoy

              Releases Tags
            Releases · envoyproxy/envoy

                Release list

                    * v1.39.0
                    * v1.38.3
                    * v1.37.5
                    * v1.36.9
                    * v1.35.13
                    * v1.38.2
                    * v1.37.4
                    * v1.36.8
                    * v1.35.12
                    * v1.38.1
                    Previous Next
                Jump to release
                        * v1.39.0
                        * v1.38.3
                        * v1.37.5
                        * v1.36.9
                        * v1.35.13
                        * v1.38.2
                        * v1.37.4
                        * v1.36.8
                        * v1.35.12
                        * v1.38.1
                    Previous Next

                v1.39.0

                              v1.39.0 Latest
                              Latest
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 14 Jul 22:03
                              v1.39.0
                              8eea328
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          Summary of changes

                          Breaking changes

                            * build: Envoy now uses Bazel 8. Because Envoy still uses WORKSPACE mode, --enable_workspace and --noenable_bzlmod are required and have been added to .bazelrc; external-repository runfiles now appear directly under the runfiles root.
                            * build: the Intel DLB connection balancer (envoy.network.connection_balance.dlb) is disabled for all builds due to a broken source archive.
                            * TLS: enforce_rsa_key_usage is deprecated and ignored; Envoy now always enforces the certificate keyUsage extension.
                            * TLS inspector: client TLS versions are validated and must be between TLS 1.0 and TLS 1.3 (revertible via envoy.reloadable_features.tls_inspector_enforce_client_tls_version).
                            * OpenTelemetry tracing: the tracer now honors Envoy's request-entry sampling decision, including overall_sampling, even when propagated trace context or the configured sampler requests sampling. This may reduce exported spans.

                          Security

                            * HTTP/2 now counts uncompressed cookies toward header-size and header-count limits (CVE-2026-47774), strengthens PRIORITY/WINDOW_UPDATE flood protection, and adds configurable nghttp2 RST_STREAM rate limits.
                            * HTTP/3 fixes cover QPACK blocked-decoding denial of service (GHSA-p7c7-7c47-pwch) and inconsistent headers-only content-length handling (CVE-2026-48743).
                            * Security fixes were added for ext_authz (CVE-2026-47205), ext_proc (CVE-2026-47207), gRPC stats (CVE-2026-47204), internal redirects (CVE-2026-47221), and OAuth2 lifecycle handling (CVE-2026-48090).
                            * OAuth2 adds AES-256-GCM cookie encryption to address CVE-2026-47775. Migration is opt-in: enable oauth2_use_gcm_encryption, monitor oauth_legacy_cbc_decrypt, then disable oauth2_legacy_cbc_decrypt_compat.
                            * Additional fixes cover DNS query validation (CVE-2026-48497), JSON nesting limits (CVE-2026-48042), PROXY protocol TLV smuggling (CVE-2026-47692), formatter crashes (CVE-2026-47220), TCP StatsD overflow (CVE-2026-48706), TLS SAN NUL handling (CVE-2026-47778), and Zstd decompression memory exhaustion (CVE-2026-48044).
                            * New upstream RBAC and dynamic-forward-proxy resolved-address filtering provide CIDR-based protection against SSRF after DNS resolution and host selection.

                          Dynamic modules

                            * New extension points: access-log/header formatters, downstream and upstream transport sockets, active health checkers, and stats sinks.
                            * Cluster load balancers can read host stats, read and write dynamic metadata and filter state, and publish main-thread state to worker-local slots.
                            * Modules can emit metrics from configuration and background contexts; loading and initialization failures now expose server-wide counters tagged by extension instance.
                            * Added validation-mode detection, network/listener attribute access, batched header and metadata APIs, effective log-level access, and zero-copy borrowed buffers in the Rust SDK.
                            * Fixed listener HTTP-callout crashes, watermark initialization, streaming-response re-entry, independent decode/encode continuation, CatchUnwind re-entry, Struct configuration handling, and HTTP/TCP bridge buffer overflow with more than 64 slices.

                          MCP (Model Context Protocol) and AI protocols

                            * Added a Wuffs-backed streaming JSON parser for MCP, A2A, OpenAI, Anthropic, and related protocols, with bounded field capture, incremental parsing, no DOM allocation, and duplicate-key detection.
                            * MCP filtering now exposes processing status, supports configurable duplicate-key rejection, and improves oversized-body behavior for pass-through and rejection modes.
                            * MCP router adds elicitation and server-to-client request routing, plus lazy per-backend initialization.
                            * MCP JSON REST Bridge adds per-route tool configuration and locally generated tools/list responses.

                          HTTP, routing and protocol

                            * New HTTP filters provide weighted bandwidth sharing and selectable sub-filter chains with per-route configuration.
                            * HeaderMatcher now evaluates separately supplied header values individually instead of matching only their comma-joined representation (revertible via envoy.reloadable_features.match_headers_individually).
                            * HTTP inspector uses Balsa by default and now fast-fails invalid non-HTTP method bytes instead of buffering up to 64 KiB.
                            * Added drain-timeout and maximum-connection-duration jitter to reduce synchronized reconnect spikes.
                            * Routing gains cluster refresh on retries, weighted-cluster reselection, formatter/CEL-based redirect paths, and mixed literal/variable URI-template segments.
                            * Fixed connection-pool re-entrancy, connectivity-grid teardown and duplicate-attempt bugs, stale on-demand cluster information, and handling of HTTP/2 or HTTP/3 RST_STREAM(NO_ERROR) after complete responses.

                          TLS, authentication and authorization

                            * Added CNSA 1.0/2.0 compliance policies, TLS group formatters for identifying post-quantum key exchange, and suppression of oversized client CA lists.
                            * QUIC supports opt-in TLS key logging and session-ticket resumption.
                            * TLS certificate compression via the brotli runtime guard is disabled by default; TLS sockets also gain improved connection-reset reporting.
                            * OAuth2 adds PRIVATE_KEY_JWT, ID-token forwarding, configurable post-logout redirects, access-token-based cookie lifetime, and safe original-request URI formatting with redirect-domain allowlists.
                            * BasicAuth supports missing-credential pass-through and authenticated-username metadata; JWT extraction can mark forwarded claims whose signatures were not verified.

                          DNS, load balancing and upstream

                            * The unified DNS cluster implementation is enabled by default; equivalent c-ares resolvers can be shared across clusters to support shared qcache.
                            * DNS clusters gain a minimum TTL refresh floor, while dynamic forward proxy sub-clusters can use DnsCluster configuration and resolved-address CIDR filtering.
                            * Client-side weighted round robin adds out-of-band ORCA reporting with configurable port, authority, and transport socket matching.
                            * Least-request load balancing can optionally account for pending requests, with a new per-endpoint pending-request gauge.
                            * Fixed EDS hostname updates, load reports containing only custom metrics or completed requests, and dynamic-forward-proxy lookup teardown.

                          Networking and system performance

                            * Linux deployments gain worker CPU affinity and an SO_REUSEPORT BPF connection balancer for CPU-local connection steering.
                            * Added a Linux sockmap socket interface for accelerating same-host TCP traffic through eBPF.
                            * io_uring adds multishot receives, adaptive read buffers, and configurable write backpressure.
                            * Reverse tunnels gain opt-in GOAWAY-aware draining and replacement; MySQL proxy adds downstream TLS termination with caching_sha2_password mediation.
                            * Added UDP proxy external authorization, network ext_proc metadata reception, and early external-processor stream closure.

                          Observability

                            * New access-log data includes upstream TLS SNI and HTTP/TCP downstream/upstream connection duration points; gRPC access logging adds delivery success/failure counters.
                            * Added dynamic-module and Wasm programmable stats sinks, OpenTelemetry metric request chunking, endpoint observability names, and default-tag overrides.
                            * Prometheus scraping and large-scale stat-reference release are substantially faster; /peak_heap_dump exposes tcmalloc's peak heap profile.
                            * Added process-wide Lua and Wasm VM gauges, single-entry stack traces, and an Envoy-version log-format token.
                            * Tap now honors configured runtime sampling and reports sampled-out requests/connections.

                          Rate limiting and configuration

                            * Rate limiting adds static and dynamic per-descriptor limit overrides, zero-token always-reject behavior, and configurable response-metadata namespaces.
                            * GCP authentication supports bound access tokens, bound JWTs, and unbound access tokens from the metadata server.
                            * Added file-backed IP tagging, in-place watched-file modification events, runtime-adjustable fixed-heap limits, health-check HTTP status events, and xDS unsubscribe callbacks.
                            * Redis proxy adds Redis 7.4 hash-field expiry commands and permits custom commands inside transactions.

                          Other notable changes and fixes

                            * Fixed Hickory DNS resolver leaks and use-after-free, file-server cancellation use-after-free, Golang filter re-entry, outlier-detection teardown, missing network namespaces, and asynchronous TLS close handling.
                            * Fixed RTDS guard removal, VHDS subscriptions, Wasm VM cache invalidation when environment variables change, and upstream Wasm metric scoping.
                            * Improved UDP proxy attempted-host and address logging, Zipkin timestamp trace IDs, gRPC access-log failure accounting, and health-check event detail.
                            * Added TCP proxy delayed route selection, drain-close handling, and connection-duration access logging.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.0
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.39.0/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.39.0/version_history/v1.39/v1.39.0
                          Full changelog:
                          v1.38.0...v1.39.0

                          Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
                          Signed-off-by: Ryan Northey ryan@synca.io
                          Signed-off-by: Jonh Wendell jwendell@redhat.com

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              👍 5 wbpcode, zhangkang0911, dmpe, i0tool5, and luisfernandomoreira reacted with thumbs up emoji ❤️ 6 wbpcode, mteslenko, zhangkang0911, alrzazz, ME-ON1, and jukie reacted with heart emoji 🚀 2 erwinkramer and i0tool5 reacted with rocket emoji
                                All reactions
                                  * 👍 5 reactions
                                  * ❤️ 6 reactions
                                  * 🚀 2 reactions
                              10 people reacted

                v1.38.3

                              v1.38.3
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 23 Jun 23:28
                              v1.38.3
                              0ebfcfe

                          Summary of changes:

                            * Security fixes:

                                + CVE-2026-47205: Authz per route crash
                                + CVE-2026-47207: ext_proc response in one gRPC message
                                + CVE-2026-47221: router internal redirects crash
                                + CVE-2026-47220: REQUESTED_SERVER_NAME crash
                                + CVE-2026-47775: OAuth2 code verifier padding oracle
                                + CVE-2026-48044: zstd RLE zip bomb
                                + CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
                                + CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
                                + CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
                                + CVE-2026-48042: Stack overflow in destructor of highly nested JSON
                                + CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
                                + CVE-2026-48497: Abnormal process termination in DNS UDP filter
                                + CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
                                + CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
                                + GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding

                            * Upstream security fixes:

                                + CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.

                            * Behavior changes:

                                + build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.

                            * Minor behavior changes:

                                + tls: runtime guard envoy.reloadable_features.tls_certificate_compression_brotli is now disabled by default. When disabled, QUIC retains zlib-only certificate compression and TCP TLS performs no certificate compression. It can be re-enabled by setting the runtime guard to true.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.3
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.38.3/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.38.3/version_history/v1.38/v1.38.3
                          Full changelog:
                          v1.38.2...v1.38.3

                          Signed-off-by: Greg Greenway ggreenway@apple.com
                          Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
                          Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
                          Signed-off-by: Ryan Northey ryan@synca.io
                          Signed-off-by: Boteng Yao boteng@google.com

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                                All reactions

                v1.37.5

                              v1.37.5
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 23 Jun 22:12
                              v1.37.5
                              f97695a

                          Summary of changes:

                            * Security fixes:

                                + CVE-2026-47205:Authz per route crash
                                + CVE-2026-47207: ext_proc response in one gRPC message
                                + CVE-2026-47221: router internal redirects crash
                                + CVE-2026-47220: REQUESTED_SERVER_NAME crash
                                + CVE-2026-47775: OAuth2 code verifier padding oracle
                                + CVE-2026-48044: zstd RLE zip bomb
                                + CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
                                + CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
                                + CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
                                + CVE-2026-48042: Stack overflow in destructor of highly nested JSON
                                + CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
                                + CVE-2026-48497: Abnormal process termination in DNS UDP filter
                                + CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
                                + CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
                                + GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding

                            * Upstream security fixes:

                                + CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.

                            * Behavior changes:

                                + build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.5
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.37.5/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.37.5/version_history/v1.37/v1.37.5
                          Full changelog:
                          v1.37.4...v1.37.5

                          Signed-off-by: Greg Greenway ggreenway@apple.com
                          Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
                          Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
                          Signed-off-by: Ryan Northey ryan@synca.io
                          Signed-off-by: Boteng Yao boteng@google.com

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                                All reactions

                v1.36.9

                              v1.36.9
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 23 Jun 20:22
                              v1.36.9
                              57198c4

                          Summary of changes:

                            * Upstream security fixes:

                                + CVE-2026-47205:Authz per route crash
                                + CVE-2026-47207: ext_proc response in one gRPC message
                                + CVE-2026-47221: router internal redirects crash
                                + CVE-2026-47775: OAuth2 code verifier padding oracle
                                + CVE-2026-48044: zstd RLE zip bomb
                                + CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
                                + CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
                                + CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
                                + CVE-2026-48042: Stack overflow in destructor of highly nested JSON
                                + CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
                                + CVE-2026-48497: Abnormal process termination in DNS UDP filter
                                + CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
                                + CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
                                + GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding

                            * Upstream security fixes:

                                + CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.

                            * Behavior changes:

                                + build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.9
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.36.9/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.36.9/version_history/v1.36/v1.36.9
                          Full changelog:
                          v1.36.8...v1.36.9

                          Signed-off-by: Greg Greenway ggreenway@apple.com
                          Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
                          Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
                          Signed-off-by: Ryan Northey ryan@synca.io
                          Signed-off-by: Boteng Yao boteng@google.com

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                                All reactions

                v1.35.13

                              v1.35.13
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 23 Jun 18:50
                              v1.35.13
                              adb998f

                          Summary of changes:

                            * Security fixes:

                                + CVE-2026-47207: ext_proc response in one gRPC message
                                + CVE-2026-47221: router internal redirects crash
                                + CVE-2026-47775: OAuth2 code verifier padding oracle
                                + CVE-2026-48044: zstd RLE zip bomb
                                + CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
                                + CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled
                                  spillover into the upstream application stream
                                + CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
                                + CVE-2026-48042: Stack overflow in destructor of highly nested JSON
                                + CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
                                + CVE-2026-48497: DNS filter abnormal process termination on long query name
                                + CVE-2026-48743: HTTP/3 headers-only request/response content-length not validated
                                + CVE-2026-48706: TcpStatsdSync buffer overflow with large stats name
                                + GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding

                            * Upstream security fixes:

                                + CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.

                            * Behavior changes:

                                + build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.13
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.35.13/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.35.13/version_history/v1.35/v1.35.13
                          Full changelog:
                          v1.35.12...v1.35.13

                          Signed-off-by: Greg Greenway ggreenway@apple.com
                          Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
                          Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
                          Signed-off-by: Ryan Northey ryan@synca.io
                          Signed-off-by: Boteng Yao boteng@google.com

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                                All reactions

                v1.38.2

                              v1.38.2
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 10 Jun 23:13
                              v1.38.2
                              f387231

                          Summary of changes:

                            * Bug fixes:

                                + runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.

                            * New features:

                                + http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
                                + http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.2
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.38.2/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.38.2/version_history/v1.38/v1.38.2
                          Full changelog:
                          v1.38.1...v1.38.2

                          Signed-off-by: Ryan Northey ryan@synca.io
                          Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              👍 1 i0tool5 reacted with thumbs up emoji 🚀 2 i0tool5 and Jing-ze reacted with rocket emoji
                                All reactions
                                  * 👍 1 reaction
                                  * 🚀 2 reactions
                              2 people reacted

                v1.37.4

                              v1.37.4
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 10 Jun 20:23
                              v1.37.4
                              4de9a4b

                          Summary of changes:

                            * Bug fixes:

                                + runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.

                            * New features:

                                + http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
                                + http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.4
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.37.4/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.37.4/version_history/v1.37/v1.37.4
                          Full changelog:
                          v1.37.3...v1.37.4

                          Signed-off-by: Ryan Northey ryan@synca.io
                          Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              👍 1 i0tool5 reacted with thumbs up emoji 🎉 1 i0tool5 reacted with hooray emoji
                                All reactions
                                  * 👍 1 reaction
                                  * 🎉 1 reaction
                              1 person reacted

                v1.36.8

                              v1.36.8
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 10 Jun 17:35
                              v1.36.8
                              ee7784f

                          Summary of changes:

                            * Bug fixes:

                                + runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.

                            * New features:

                                + http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
                                + http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.8
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.36.8/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.36.8/version_history/v1.36/v1.36.8
                          Full changelog:
                          v1.36.7...v1.36.8

                          Signed-off-by: Ryan Northey ryan@synca.io
                          Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              ❤️ 2 peterhirn and i0tool5 reacted with heart emoji
                                All reactions
                                  * ❤️ 2 reactions
                              2 people reacted

                v1.35.12

                              v1.35.12
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 10 Jun 14:01
                              v1.35.12
                              fb1b0d0

                          Summary of changes:

                            * Bug fixes:

                                + runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.

                            * New features:

                                + http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
                                + http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.12
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.35.12/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.35.12/version_history/v1.35/v1.35.12
                          Full changelog:
                          v1.35.11...v1.35.12

                          Signed-off-by: Ryan Northey ryan@synca.io
                          Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              ❤️ 2 peterhirn and i0tool5 reacted with heart emoji
                                All reactions
                                  * ❤️ 2 reactions
                              2 people reacted

                v1.38.1

                              v1.38.1
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              publish-envoy released this 04 Jun 19:28
                              v1.38.1
                              5022e0b

                          Summary of changes:

                            * Security fixes:

                                + CVE-2026-47774: http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards mutable_max_request_headers_kb and max_headers_count limits, protecting against an HPACK cookie-bomb that could cause excessive memory usage. This can be reverted with envoy.reloadable_features.http2_include_cookies_in_limits.
                                + oauth2: fixed a timing side-channel in HMAC verification that could leak HMAC secret validity.
                                + oauth2: fixed a crash where AES-CBC decryption of token cookies could spuriously succeed (~1/256) on a secret mismatch, tripping a HeaderString validation assert.
                                + CVE-2026-27135: http2: applied nghttp2 CVE-2026-27135 patch.

                            * Bug fixes:

                                + dynamic_modules: fixed a crash in the HTTP filter when a stream was already above the downstream write-buffer high watermark at filter-chain construction time.

                            * Minor behavior changes:

                                + router: the upstream transport failure reason is no longer included in the HTTP response body sent to downstream clients (still available in access logs via %UPSTREAM_TRANSPORT_FAILURE_REASON%). Revert with envoy.reloadable_features.hide_transport_failure_reason_in_response_body.
                                + upstream: load balancer rebuild coalescing during EDS batch host updates is now opt-in. Re-enable with envoy.reloadable_features.coalesce_lb_rebuilds_on_batch_update.

                          Docker images:
                          https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.1
                          Docs:
                          https://www.envoyproxy.io/docs/envoy/v1.38.1/
                          Release notes:
                          https://www.envoyproxy.io/docs/envoy/v1.38.1/version_history/v1.38/v1.38.1
                          Full changelog:
                          v1.38.0...v1.38.1

                          Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
                          Signed-off-by: Greg Greenway ggreenway@apple.com
                          Signed-off-by: Ryan Northey ryan@synca.io

                          Assets 8
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                                All reactions
                Previous 1 2 3 4 5 … 27 28 Next
                Previous Next

  Footer

      © 2026 GitHub, Inc.

    Footer navigation

      * Terms
      * Privacy
      * Security
      * Status
      * Community
      * Docs
      * Contact
      * Manage cookies
      * Do not share my personal information
    You can’t perform that action at this time.
For now, Differences are performed on text, not graphically, only the latest screenshot is available.

Screenshot requires a Content Fetcher ( Sockpuppetbrowser, selenium, etc ) that supports screenshots.