v1.39.1

2026-08-27T08:52:18Z3778d4281f9bc056ecb7b7471651f485a3152f0e3047e5a995d47a90f35f4d6f
CVE-2026-47204CVE-2026-47205CVE-2026-47207CVE-2026-47220CVE-2026-47221CVE-2026-47692CVE-2026-47774CVE-2026-47775CVE-2026-47778CVE-2026-48042CVE-2026-48044CVE-2026-48090CVE-2026-48743CVE-2026-73511CVE-2026-73512CVE-2026-73513CVE-2026-73546CVE-2026-73547CVE-2026-73548CVE-2026-73549CVE-2026-73550EnvoyEnvoy ProxyHTTP upgradeHTTP/2HTTP/3OAuth2PROXY protocolQUICTLSURL normalizationadmin interfaceconnection poisoningcrashdenial of serviceext_authzheader limitssecurity releaseuse-after-freezstd

What happened

Envoy Proxy security releases v1.39.1, v1.38.4, v1.37.6, and v1.36.10 address multiple vulnerabilities, including URL normalization issues, HTTP/2 and HTTP/3 denial-of-service or crash conditions, HTTP/3 use-after-free, admin HTML injection risk, ext_authz crashes, HTTP upgrade connection poisoning, QUIC IPv6 handling crashes, and header-limit bypass behavior. Earlier related releases also remediate OAuth2, ext_proc, gRPC stats, internal redirect, zstd decompression, PROXY protocol, TLS SAN validation, JSON parsing, and other flaws. Users should upgrade to the latest maintained Envoy patch for

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
envoyproxy_envoy_releases
Record identifier
3778d4281f9bc056ecb7b7471651f485a3152f0e3047e5a995d47a90f35f4d6f
Enrichment time
2026-08-27T08:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.