v1.39.0
2026-07-16T08:52:33Z•a6beddc18ed04729ec684c68cc31a416d1512e7fa82d09ca620147805c63aee5
bazelcrashdenial-of-serviceenvoyext_authzext_procgrpchttp2http3oauth2open-telemetryproxy-protocolqpackreleasesecuritytlszstd
What happened
Envoy releases (notably v1.39.0 and several 1.35–1.38.x patch releases) introduce multiple breaking/build changes (Bazel 8 requirement, Intel DLB disabled), TLS behavior changes (always-enforce keyUsage, TLS inspector enforces client TLS versions), and OpenTelemetry sampling behavior changes. Important security hardening includes HTTP/2 header-size/count accounting for uncompressed cookies, stronger PRIORITY/WINDOW_UPDATE flood protections, configurable nghttp2 RST_STREAM rate limits, HTTP/3 fixes for QPACK blocked-decoding DoS and headers-only content-length handling, and numerous fixes for—e
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- envoyproxy_envoy_releases
- Record identifier
- a6beddc18ed04729ec684c68cc31a416d1512e7fa82d09ca620147805c63aee5
- Enrichment time
- 2026-07-16T08:52:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.