v1.37.1
2026-03-11T08:52:32Z•bc89923851cec88f387aa62431432aabc2aa3e5e0d6ae49589da9748e100ff95
access-logauth-bypassc-arescrashdependency-updateenvoyext_authzipv6jsonmemory-corruptionoauth2rate-limitingrbacreleasesecurity-fix
What happened
Envoy released multiple patch versions (notably v1.37.1, v1.36.5, v1.35.9, v1.34.13) that include several security fixes and dependency updates. Fixed issues include: CVE-2026-26330 (rate-limit response-phase bug that could crash Envoy), CVE-2026-26308 (RBAC multivalue header bypass — authorization bypass risk), CVE-2026-26310 (crash when getAddressWithPort() is called with scoped IPv6 addresses), CVE-2026-26309 (JSON off-by-one write that can corrupt string terminator — memory corruption), CVE-2026-26311 (HTTP decode* methods forced after downstream reset), and earlier dependency fixes for c-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- envoyproxy_envoy_releases
- Record identifier
- bc89923851cec88f387aa62431432aabc2aa3e5e0d6ae49589da9748e100ff95
- Enrichment time
- 2026-03-11T08:52:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.