v1.39.0

2026-07-16T08:52:33Za6beddc18ed04729ec684c68cc31a416d1512e7fa82d09ca620147805c63aee5
bazelcrashdenial-of-serviceenvoyext_authzext_procgrpchttp2http3oauth2open-telemetryproxy-protocolqpackreleasesecuritytlszstd

What happened

Envoy releases (notably v1.39.0 and several 1.35–1.38.x patch releases) introduce multiple breaking/build changes (Bazel 8 requirement, Intel DLB disabled), TLS behavior changes (always-enforce keyUsage, TLS inspector enforces client TLS versions), and OpenTelemetry sampling behavior changes. Important security hardening includes HTTP/2 header-size/count accounting for uncompressed cookies, stronger PRIORITY/WINDOW_UPDATE flood protections, configurable nghttp2 RST_STREAM rate limits, HTTP/3 fixes for QPACK blocked-decoding DoS and headers-only content-length handling, and numerous fixes for—e

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
envoyproxy_envoy_releases
Record identifier
a6beddc18ed04729ec684c68cc31a416d1512e7fa82d09ca620147805c63aee5
Enrichment time
2026-07-16T08:52:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.