v1.38.3

2026-06-25T08:52:31Za3e5097b326961a78ccda29d1170ed93943ab137e48d7f9db1bb2ab1cc715cd3
CVEauth-bypasscrashdenial-of-servicednsenvoyhttp3oauth2padding-oracleproxy-protocolreleasesecuritystack-overflowtlsuse-after-freezip-bombzstd

What happened

Envoy published multiple patch releases (notably v1.38.3, v1.37.5, v1.36.9, v1.35.13 and others) that fix a broad set of security issues. Remediations address crashes and use-after-free conditions, denial-of-service/vector amplification (zstd RLE “zip bomb”, stack overflow, DNS filter termination), authentication/authorization bypasses (TLS SAN truncation, REQUESTED_SERVER_NAME crash), an OAuth2 code verifier padding-oracle, PROXY Protocol v2 header TLV spillover (65 KB attacker-controlled spillover into upstream), gRPC/Connect segfaults, and HTTP/3 header validation issues. Administrators are

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
envoyproxy_envoy_releases
Record identifier
a3e5097b326961a78ccda29d1170ed93943ab137e48d7f9db1bb2ab1cc715cd3
Enrichment time
2026-06-25T08:52:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · v1.38.3 · Baitaphish