v1.38.3
2026-06-25T08:52:31Z•a3e5097b326961a78ccda29d1170ed93943ab137e48d7f9db1bb2ab1cc715cd3
CVEauth-bypasscrashdenial-of-servicednsenvoyhttp3oauth2padding-oracleproxy-protocolreleasesecuritystack-overflowtlsuse-after-freezip-bombzstd
What happened
Envoy published multiple patch releases (notably v1.38.3, v1.37.5, v1.36.9, v1.35.13 and others) that fix a broad set of security issues. Remediations address crashes and use-after-free conditions, denial-of-service/vector amplification (zstd RLE “zip bomb”, stack overflow, DNS filter termination), authentication/authorization bypasses (TLS SAN truncation, REQUESTED_SERVER_NAME crash), an OAuth2 code verifier padding-oracle, PROXY Protocol v2 header TLV spillover (65 KB attacker-controlled spillover into upstream), gRPC/Connect segfaults, and HTTP/3 header validation issues. Administrators are
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- envoyproxy_envoy_releases
- Record identifier
- a3e5097b326961a78ccda29d1170ed93943ab137e48d7f9db1bb2ab1cc715cd3
- Enrichment time
- 2026-06-25T08:52:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.