Try our Chrome extension
Easily add the current web-page from your browser directly into your changedetection.io tool, more great features coming soon!Changedetection.io needs your support!
You can help us by supporting changedetection.io on these platforms;
- Rate us at AlternativeTo.net
- Star us on GitHub
- Follow us at Twitter/X
- G2 Software reviews
- Check us out on LinkedIn
- And tell your friends and colleagues :)
The more popular changedetection.io is, the more time we can dedicate to adding amazing features!
Many thanks :)
changedetection.io team
Not yet seconds ago.
False
Not yet seconds ago
16 hours agoGoto single snapshot
Skip to content
Navigation Menu
Sign in Appearance settings
* Platform
+ AI CODE CREATION
o GitHub Copilot Write better code with AI
o GitHub Copilot app Direct agents from issue to merge
o MCP Registry Integrate external tools
+ DEVELOPER WORKFLOWS
o Actions Automate any workflow
o Codespaces Instant dev environments
o Issues Plan and track work
o Code Review Manage code changes
o Code Quality Enforce quality at merge
+ APPLICATION SECURITY
o GitHub Advanced Security Find and fix vulnerabilities
o Code security Secure your code as you build
o Secret protection Stop leaks before they start
+ EXPLORE
o Why GitHub
o Documentation
o Blog
o Changelog
o Marketplace
View all features
* Solutions
+ BY COMPANY SIZE
o Enterprises
o Small and medium teams
o Startups
o Nonprofits
+ BY USE CASE
o App Modernization
o DevSecOps
o DevOps
o CI/CD
o View all use cases
+ BY INDUSTRY
o Healthcare
o Financial services
o Manufacturing
o Government
o View all industries
View all solutions
* Resources
+ EXPLORE BY TOPIC
o AI
o Software Development
o DevOps
o Security
o View all topics
+ EXPLORE BY TYPE
o Customer stories
o Events & webinars
o Ebooks & reports
o Business insights
o GitHub Skills
+ SUPPORT & SERVICES
o Documentation
o Customer support
o Community forum
o Trust center
o Partners
View all resources
* Open Source
+ COMMUNITY
o GitHub Sponsors Fund open source developers
+ PROGRAMS
o Security Lab
o Maintainer Community
o Accelerator
o GitHub Stars
o Archive Program
+ REPOSITORIES
o Topics
o Trending
o Collections
* Enterprise
+ ENTERPRISE SOLUTIONS
o Enterprise platform AI-powered developer platform
+ AVAILABLE ADD-ONS
o GitHub Advanced Security Enterprise-grade security features
o Copilot for Business Enterprise-grade AI features
o Premium Support Enterprise-grade 24/7 support
* Pricing
Type / to search
Sign in
Sign up Appearance settings
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
Uh oh!
There was an error while loading. Please reload this page.
envoyproxy / envoy Public
* Notifications You must be signed in to change notification settings
* Fork 5.5k
* Star 28.7k
* Code
* Issues 1.6k
* Pull requests 203
* Pull requests 204
* Discussions
* Actions
* Projects
* Wiki
* Security and quality 117
* Insights
Additional navigation options
* Code
* Issues
* Pull requests
* Discussions
* Actions
* Projects
* Wiki
* Security and quality
* Insights
Releases: envoyproxy/envoy
Releases Tags
Releases · envoyproxy/envoy
Release list
* v1.39.0
* v1.38.3
* v1.37.5
* v1.36.9
* v1.35.13
* v1.38.2
* v1.37.4
* v1.36.8
* v1.35.12
* v1.38.1
Previous Next
Jump to release
* v1.39.0
* v1.38.3
* v1.37.5
* v1.36.9
* v1.35.13
* v1.38.2
* v1.37.4
* v1.36.8
* v1.35.12
* v1.38.1
Previous Next
v1.39.0
v1.39.0 Latest
Latest
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 14 Jul 22:03
v1.39.0
8eea328
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Summary of changes
Breaking changes
* build: Envoy now uses Bazel 8. Because Envoy still uses WORKSPACE mode, --enable_workspace and --noenable_bzlmod are required and have been added to .bazelrc; external-repository runfiles now appear directly under the runfiles root.
* build: the Intel DLB connection balancer (envoy.network.connection_balance.dlb) is disabled for all builds due to a broken source archive.
* TLS: enforce_rsa_key_usage is deprecated and ignored; Envoy now always enforces the certificate keyUsage extension.
* TLS inspector: client TLS versions are validated and must be between TLS 1.0 and TLS 1.3 (revertible via envoy.reloadable_features.tls_inspector_enforce_client_tls_version).
* OpenTelemetry tracing: the tracer now honors Envoy's request-entry sampling decision, including overall_sampling, even when propagated trace context or the configured sampler requests sampling. This may reduce exported spans.
Security
* HTTP/2 now counts uncompressed cookies toward header-size and header-count limits (CVE-2026-47774), strengthens PRIORITY/WINDOW_UPDATE flood protection, and adds configurable nghttp2 RST_STREAM rate limits.
* HTTP/3 fixes cover QPACK blocked-decoding denial of service (GHSA-p7c7-7c47-pwch) and inconsistent headers-only content-length handling (CVE-2026-48743).
* Security fixes were added for ext_authz (CVE-2026-47205), ext_proc (CVE-2026-47207), gRPC stats (CVE-2026-47204), internal redirects (CVE-2026-47221), and OAuth2 lifecycle handling (CVE-2026-48090).
* OAuth2 adds AES-256-GCM cookie encryption to address CVE-2026-47775. Migration is opt-in: enable oauth2_use_gcm_encryption, monitor oauth_legacy_cbc_decrypt, then disable oauth2_legacy_cbc_decrypt_compat.
* Additional fixes cover DNS query validation (CVE-2026-48497), JSON nesting limits (CVE-2026-48042), PROXY protocol TLV smuggling (CVE-2026-47692), formatter crashes (CVE-2026-47220), TCP StatsD overflow (CVE-2026-48706), TLS SAN NUL handling (CVE-2026-47778), and Zstd decompression memory exhaustion (CVE-2026-48044).
* New upstream RBAC and dynamic-forward-proxy resolved-address filtering provide CIDR-based protection against SSRF after DNS resolution and host selection.
Dynamic modules
* New extension points: access-log/header formatters, downstream and upstream transport sockets, active health checkers, and stats sinks.
* Cluster load balancers can read host stats, read and write dynamic metadata and filter state, and publish main-thread state to worker-local slots.
* Modules can emit metrics from configuration and background contexts; loading and initialization failures now expose server-wide counters tagged by extension instance.
* Added validation-mode detection, network/listener attribute access, batched header and metadata APIs, effective log-level access, and zero-copy borrowed buffers in the Rust SDK.
* Fixed listener HTTP-callout crashes, watermark initialization, streaming-response re-entry, independent decode/encode continuation, CatchUnwind re-entry, Struct configuration handling, and HTTP/TCP bridge buffer overflow with more than 64 slices.
MCP (Model Context Protocol) and AI protocols
* Added a Wuffs-backed streaming JSON parser for MCP, A2A, OpenAI, Anthropic, and related protocols, with bounded field capture, incremental parsing, no DOM allocation, and duplicate-key detection.
* MCP filtering now exposes processing status, supports configurable duplicate-key rejection, and improves oversized-body behavior for pass-through and rejection modes.
* MCP router adds elicitation and server-to-client request routing, plus lazy per-backend initialization.
* MCP JSON REST Bridge adds per-route tool configuration and locally generated tools/list responses.
HTTP, routing and protocol
* New HTTP filters provide weighted bandwidth sharing and selectable sub-filter chains with per-route configuration.
* HeaderMatcher now evaluates separately supplied header values individually instead of matching only their comma-joined representation (revertible via envoy.reloadable_features.match_headers_individually).
* HTTP inspector uses Balsa by default and now fast-fails invalid non-HTTP method bytes instead of buffering up to 64 KiB.
* Added drain-timeout and maximum-connection-duration jitter to reduce synchronized reconnect spikes.
* Routing gains cluster refresh on retries, weighted-cluster reselection, formatter/CEL-based redirect paths, and mixed literal/variable URI-template segments.
* Fixed connection-pool re-entrancy, connectivity-grid teardown and duplicate-attempt bugs, stale on-demand cluster information, and handling of HTTP/2 or HTTP/3 RST_STREAM(NO_ERROR) after complete responses.
TLS, authentication and authorization
* Added CNSA 1.0/2.0 compliance policies, TLS group formatters for identifying post-quantum key exchange, and suppression of oversized client CA lists.
* QUIC supports opt-in TLS key logging and session-ticket resumption.
* TLS certificate compression via the brotli runtime guard is disabled by default; TLS sockets also gain improved connection-reset reporting.
* OAuth2 adds PRIVATE_KEY_JWT, ID-token forwarding, configurable post-logout redirects, access-token-based cookie lifetime, and safe original-request URI formatting with redirect-domain allowlists.
* BasicAuth supports missing-credential pass-through and authenticated-username metadata; JWT extraction can mark forwarded claims whose signatures were not verified.
DNS, load balancing and upstream
* The unified DNS cluster implementation is enabled by default; equivalent c-ares resolvers can be shared across clusters to support shared qcache.
* DNS clusters gain a minimum TTL refresh floor, while dynamic forward proxy sub-clusters can use DnsCluster configuration and resolved-address CIDR filtering.
* Client-side weighted round robin adds out-of-band ORCA reporting with configurable port, authority, and transport socket matching.
* Least-request load balancing can optionally account for pending requests, with a new per-endpoint pending-request gauge.
* Fixed EDS hostname updates, load reports containing only custom metrics or completed requests, and dynamic-forward-proxy lookup teardown.
Networking and system performance
* Linux deployments gain worker CPU affinity and an SO_REUSEPORT BPF connection balancer for CPU-local connection steering.
* Added a Linux sockmap socket interface for accelerating same-host TCP traffic through eBPF.
* io_uring adds multishot receives, adaptive read buffers, and configurable write backpressure.
* Reverse tunnels gain opt-in GOAWAY-aware draining and replacement; MySQL proxy adds downstream TLS termination with caching_sha2_password mediation.
* Added UDP proxy external authorization, network ext_proc metadata reception, and early external-processor stream closure.
Observability
* New access-log data includes upstream TLS SNI and HTTP/TCP downstream/upstream connection duration points; gRPC access logging adds delivery success/failure counters.
* Added dynamic-module and Wasm programmable stats sinks, OpenTelemetry metric request chunking, endpoint observability names, and default-tag overrides.
* Prometheus scraping and large-scale stat-reference release are substantially faster; /peak_heap_dump exposes tcmalloc's peak heap profile.
* Added process-wide Lua and Wasm VM gauges, single-entry stack traces, and an Envoy-version log-format token.
* Tap now honors configured runtime sampling and reports sampled-out requests/connections.
Rate limiting and configuration
* Rate limiting adds static and dynamic per-descriptor limit overrides, zero-token always-reject behavior, and configurable response-metadata namespaces.
* GCP authentication supports bound access tokens, bound JWTs, and unbound access tokens from the metadata server.
* Added file-backed IP tagging, in-place watched-file modification events, runtime-adjustable fixed-heap limits, health-check HTTP status events, and xDS unsubscribe callbacks.
* Redis proxy adds Redis 7.4 hash-field expiry commands and permits custom commands inside transactions.
Other notable changes and fixes
* Fixed Hickory DNS resolver leaks and use-after-free, file-server cancellation use-after-free, Golang filter re-entry, outlier-detection teardown, missing network namespaces, and asynchronous TLS close handling.
* Fixed RTDS guard removal, VHDS subscriptions, Wasm VM cache invalidation when environment variables change, and upstream Wasm metric scoping.
* Improved UDP proxy attempted-host and address logging, Zipkin timestamp trace IDs, gRPC access-log failure accounting, and health-check event detail.
* Added TCP proxy delayed route selection, drain-close handling, and connection-duration access logging.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.0
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.0/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.0/version_history/v1.39/v1.39.0
Full changelog:
v1.38.0...v1.39.0
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Jonh Wendell jwendell@redhat.com
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 5 wbpcode, zhangkang0911, dmpe, i0tool5, and luisfernandomoreira reacted with thumbs up emoji ❤️ 6 wbpcode, mteslenko, zhangkang0911, alrzazz, ME-ON1, and jukie reacted with heart emoji 🚀 2 erwinkramer and i0tool5 reacted with rocket emoji
All reactions
* 👍 5 reactions
* ❤️ 6 reactions
* 🚀 2 reactions
10 people reacted
v1.38.3
v1.38.3
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 23 Jun 23:28
v1.38.3
0ebfcfe
Summary of changes:
* Security fixes:
+ CVE-2026-47205: Authz per route crash
+ CVE-2026-47207: ext_proc response in one gRPC message
+ CVE-2026-47221: router internal redirects crash
+ CVE-2026-47220: REQUESTED_SERVER_NAME crash
+ CVE-2026-47775: OAuth2 code verifier padding oracle
+ CVE-2026-48044: zstd RLE zip bomb
+ CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
+ CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
+ CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
+ CVE-2026-48042: Stack overflow in destructor of highly nested JSON
+ CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
+ CVE-2026-48497: Abnormal process termination in DNS UDP filter
+ CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
+ CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
+ GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
* Upstream security fixes:
+ CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.
* Behavior changes:
+ build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.
* Minor behavior changes:
+ tls: runtime guard envoy.reloadable_features.tls_certificate_compression_brotli is now disabled by default. When disabled, QUIC retains zlib-only certificate compression and TCP TLS performs no certificate compression. It can be re-enabled by setting the runtime guard to true.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.3
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.3/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.3/version_history/v1.38/v1.38.3
Full changelog:
v1.38.2...v1.38.3
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Boteng Yao boteng@google.com
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v1.37.5
v1.37.5
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 23 Jun 22:12
v1.37.5
f97695a
Summary of changes:
* Security fixes:
+ CVE-2026-47205:Authz per route crash
+ CVE-2026-47207: ext_proc response in one gRPC message
+ CVE-2026-47221: router internal redirects crash
+ CVE-2026-47220: REQUESTED_SERVER_NAME crash
+ CVE-2026-47775: OAuth2 code verifier padding oracle
+ CVE-2026-48044: zstd RLE zip bomb
+ CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
+ CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
+ CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
+ CVE-2026-48042: Stack overflow in destructor of highly nested JSON
+ CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
+ CVE-2026-48497: Abnormal process termination in DNS UDP filter
+ CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
+ CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
+ GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
* Upstream security fixes:
+ CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.
* Behavior changes:
+ build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.5
Docs:
https://www.envoyproxy.io/docs/envoy/v1.37.5/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.37.5/version_history/v1.37/v1.37.5
Full changelog:
v1.37.4...v1.37.5
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Boteng Yao boteng@google.com
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v1.36.9
v1.36.9
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 23 Jun 20:22
v1.36.9
57198c4
Summary of changes:
* Upstream security fixes:
+ CVE-2026-47205:Authz per route crash
+ CVE-2026-47207: ext_proc response in one gRPC message
+ CVE-2026-47221: router internal redirects crash
+ CVE-2026-47775: OAuth2 code verifier padding oracle
+ CVE-2026-48044: zstd RLE zip bomb
+ CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
+ CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
+ CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
+ CVE-2026-48042: Stack overflow in destructor of highly nested JSON
+ CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
+ CVE-2026-48497: Abnormal process termination in DNS UDP filter
+ CVE-2026-48743: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
+ CVE-2026-48706: Envoy Heap Buffer Overflow in TcpStatsdSink
+ GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
* Upstream security fixes:
+ CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.
* Behavior changes:
+ build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.9
Docs:
https://www.envoyproxy.io/docs/envoy/v1.36.9/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.36.9/version_history/v1.36/v1.36.9
Full changelog:
v1.36.8...v1.36.9
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Boteng Yao boteng@google.com
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v1.35.13
v1.35.13
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 23 Jun 18:50
v1.35.13
adb998f
Summary of changes:
* Security fixes:
+ CVE-2026-47207: ext_proc response in one gRPC message
+ CVE-2026-47221: router internal redirects crash
+ CVE-2026-47775: OAuth2 code verifier padding oracle
+ CVE-2026-48044: zstd RLE zip bomb
+ CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
+ CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled
spillover into the upstream application stream
+ CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
+ CVE-2026-48042: Stack overflow in destructor of highly nested JSON
+ CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
+ CVE-2026-48497: DNS filter abnormal process termination on long query name
+ CVE-2026-48743: HTTP/3 headers-only request/response content-length not validated
+ CVE-2026-48706: TcpStatsdSync buffer overflow with large stats name
+ GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
* Upstream security fixes:
+ CVE-2026-47261: wasm: bumped com_github_wasmtime to resolve CVE-2026-47261.
* Behavior changes:
+ build: disabled the contrib extension envoy.network.connection_balance.dlb (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.13
Docs:
https://www.envoyproxy.io/docs/envoy/v1.35.13/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.35.13/version_history/v1.35/v1.35.13
Full changelog:
v1.35.12...v1.35.13
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Boteng Yao boteng@google.com
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v1.38.2
v1.38.2
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 10 Jun 23:13
v1.38.2
f387231
Summary of changes:
* Bug fixes:
+ runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
* New features:
+ http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
+ http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.2
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.2/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.2/version_history/v1.38/v1.38.2
Full changelog:
v1.38.1...v1.38.2
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 1 i0tool5 reacted with thumbs up emoji 🚀 2 i0tool5 and Jing-ze reacted with rocket emoji
All reactions
* 👍 1 reaction
* 🚀 2 reactions
2 people reacted
v1.37.4
v1.37.4
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 10 Jun 20:23
v1.37.4
4de9a4b
Summary of changes:
* Bug fixes:
+ runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
* New features:
+ http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
+ http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.4
Docs:
https://www.envoyproxy.io/docs/envoy/v1.37.4/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.37.4/version_history/v1.37/v1.37.4
Full changelog:
v1.37.3...v1.37.4
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 1 i0tool5 reacted with thumbs up emoji 🎉 1 i0tool5 reacted with hooray emoji
All reactions
* 👍 1 reaction
* 🎉 1 reaction
1 person reacted
v1.36.8
v1.36.8
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 10 Jun 17:35
v1.36.8
ee7784f
Summary of changes:
* Bug fixes:
+ runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
* New features:
+ http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
+ http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.8
Docs:
https://www.envoyproxy.io/docs/envoy/v1.36.8/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.36.8/version_history/v1.36/v1.36.8
Full changelog:
v1.36.7...v1.36.8
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
❤️ 2 peterhirn and i0tool5 reacted with heart emoji
All reactions
* ❤️ 2 reactions
2 people reacted
v1.35.12
v1.35.12
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 10 Jun 14:01
v1.35.12
fb1b0d0
Summary of changes:
* Bug fixes:
+ runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.
* New features:
+ http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled cookie header length, and individual cookie header count. Enable with envoy.reloadable_features.http2_record_histograms; the histograms and runtime guard will be removed in a future Envoy release.
+ http2: added envoy.reloadable_features.http2_max_cookies_size_in_kb to limit the size of the reassembled cookie header. By default, no cookie-size limit is enforced.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.12
Docs:
https://www.envoyproxy.io/docs/envoy/v1.35.12/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.35.12/version_history/v1.35/v1.35.12
Full changelog:
v1.35.11...v1.35.12
Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
❤️ 2 peterhirn and i0tool5 reacted with heart emoji
All reactions
* ❤️ 2 reactions
2 people reacted
v1.38.1
v1.38.1
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
publish-envoy released this 04 Jun 19:28
v1.38.1
5022e0b
Summary of changes:
* Security fixes:
+ CVE-2026-47774: http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards mutable_max_request_headers_kb and max_headers_count limits, protecting against an HPACK cookie-bomb that could cause excessive memory usage. This can be reverted with envoy.reloadable_features.http2_include_cookies_in_limits.
+ oauth2: fixed a timing side-channel in HMAC verification that could leak HMAC secret validity.
+ oauth2: fixed a crash where AES-CBC decryption of token cookies could spuriously succeed (~1/256) on a secret mismatch, tripping a HeaderString validation assert.
+ CVE-2026-27135: http2: applied nghttp2 CVE-2026-27135 patch.
* Bug fixes:
+ dynamic_modules: fixed a crash in the HTTP filter when a stream was already above the downstream write-buffer high watermark at filter-chain construction time.
* Minor behavior changes:
+ router: the upstream transport failure reason is no longer included in the HTTP response body sent to downstream clients (still available in access logs via %UPSTREAM_TRANSPORT_FAILURE_REASON%). Revert with envoy.reloadable_features.hide_transport_failure_reason_in_response_body.
+ upstream: load balancer rebuild coalescing during EDS batch host updates is now opt-in. Re-enable with envoy.reloadable_features.coalesce_lb_rebuilds_on_batch_update.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.1
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.1/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.1/version_history/v1.38/v1.38.1
Full changelog:
v1.38.0...v1.38.1
Signed-off-by: Jonh Wendell jonh.wendell@redhat.com
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Ryan Northey ryan@synca.io
Assets 8
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
Previous 1 2 3 4 5 … 27 28 Next
Previous Next
Footer
© 2026 GitHub, Inc.
Footer navigation
* Terms
* Privacy
* Security
* Status
* Community
* Docs
* Contact
* Manage cookies
* Do not share my personal information
You can’t perform that action at this time.
Tip: Highlight text to share or add to ignore lists.
— Download difference patch
For now, Differences are performed on text, not graphically, only the latest screenshot is available.
Screenshot requires Playwright/WebDriver enabled