v1.39.1
2026-08-27T08:52:18Z•3778d4281f9bc056ecb7b7471651f485a3152f0e3047e5a995d47a90f35f4d6f
CVE-2026-47204CVE-2026-47205CVE-2026-47207CVE-2026-47220CVE-2026-47221CVE-2026-47692CVE-2026-47774CVE-2026-47775CVE-2026-47778CVE-2026-48042CVE-2026-48044CVE-2026-48090CVE-2026-48743CVE-2026-73511CVE-2026-73512CVE-2026-73513CVE-2026-73546CVE-2026-73547CVE-2026-73548CVE-2026-73549CVE-2026-73550EnvoyEnvoy ProxyHTTP upgradeHTTP/2HTTP/3OAuth2PROXY protocolQUICTLSURL normalizationadmin interfaceconnection poisoningcrashdenial of serviceext_authzheader limitssecurity releaseuse-after-freezstd
What happened
Envoy Proxy security releases v1.39.1, v1.38.4, v1.37.6, and v1.36.10 address multiple vulnerabilities, including URL normalization issues, HTTP/2 and HTTP/3 denial-of-service or crash conditions, HTTP/3 use-after-free, admin HTML injection risk, ext_authz crashes, HTTP upgrade connection poisoning, QUIC IPv6 handling crashes, and header-limit bypass behavior. Earlier related releases also remediate OAuth2, ext_proc, gRPC stats, internal redirect, zstd decompression, PROXY protocol, TLS SAN validation, JSON parsing, and other flaws. Users should upgrade to the latest maintained Envoy patch for
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- envoyproxy_envoy_releases
- Record identifier
- 3778d4281f9bc056ecb7b7471651f485a3152f0e3047e5a995d47a90f35f4d6f
- Enrichment time
- 2026-08-27T08:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.