v1.37.1

2026-03-11T08:52:32Zbc89923851cec88f387aa62431432aabc2aa3e5e0d6ae49589da9748e100ff95
access-logauth-bypassc-arescrashdependency-updateenvoyext_authzipv6jsonmemory-corruptionoauth2rate-limitingrbacreleasesecurity-fix

What happened

Envoy released multiple patch versions (notably v1.37.1, v1.36.5, v1.35.9, v1.34.13) that include several security fixes and dependency updates. Fixed issues include: CVE-2026-26330 (rate-limit response-phase bug that could crash Envoy), CVE-2026-26308 (RBAC multivalue header bypass — authorization bypass risk), CVE-2026-26310 (crash when getAddressWithPort() is called with scoped IPv6 addresses), CVE-2026-26309 (JSON off-by-one write that can corrupt string terminator — memory corruption), CVE-2026-26311 (HTTP decode* methods forced after downstream reset), and earlier dependency fixes for c-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
envoyproxy_envoy_releases
Record identifier
bc89923851cec88f387aa62431432aabc2aa3e5e0d6ae49589da9748e100ff95
Enrichment time
2026-03-11T08:52:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · v1.37.1 · Baitaphish