v1.38.2

2026-06-11T08:52:30Zba1467cd2e90b1be57943c9df64200a6358f0071f4638f5ce90a1eb4eb299ea2
AES-CBCCVE-2026-27135CVE-2026-47774DoSHMACcookie-bombenvoyenvoy.reloadable_featureshpackhttp2nghttp2oauth2releaseruntime-flagssecurity-fix

What happened

Envoy release collection (v1.35.11 through v1.38.2) containing multiple security fixes and bug/feature changes. Notable security fixes: CVE-2026-47774 — HTTP/2: streams now reset when exceeding configured maximum header-list size and uncompressed cookies are included in mutable_max_request_headers_kb and max_headers_count limits to mitigate an HPACK "cookie-bomb" (memory-exhaustion/DoS). CVE-2026-27135 — applied nghttp2 patch. Additional fixes: oauth2 HMAC timing side-channel and an AES-CBC token-cookie decryption crash (~1/256 false-positive decryption on secret mismatch). Releases also add/t

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
envoyproxy_envoy_releases
Record identifier
ba1467cd2e90b1be57943c9df64200a6358f0071f4638f5ce90a1eb4eb299ea2
Enrichment time
2026-06-11T08:52:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.