v1.39.1
2026-08-28T08:52:17Z•de007cfe7e03216e68d8fb86fbfab726eb9abf6690b0691cbb655937918ca58b
CVE-2026-47204CVE-2026-47205CVE-2026-47207CVE-2026-47220CVE-2026-47221CVE-2026-47692CVE-2026-47774CVE-2026-47775CVE-2026-47778CVE-2026-48042CVE-2026-48044CVE-2026-48090CVE-2026-48743CVE-2026-73511CVE-2026-73512CVE-2026-73513CVE-2026-73546CVE-2026-73547CVE-2026-73548CVE-2026-73549CVE-2026-73550EnvoyEnvoy ProxyHTML injectionHTTP/1.1HTTP/2HTTP/3QUICURL normalizationadmin interfaceconnection poisoningcrashdenial of serviceext_authzprotocol parsingrequest smugglingsecurity releaseuse-after-free
What happened
Envoy Proxy security releases v1.39.1, v1.38.4, v1.37.6, and v1.36.10 address multiple vulnerabilities across HTTP/1, HTTP/2, HTTP/3, QUIC, URL normalization, ext_authz, and the admin interface. Issues include use-after-free, crashes or abnormal termination, request smuggling and connection poisoning, HTML injection, and protocol/resource-limit handling weaknesses. The document also references earlier security fixes in v1.39.0 and maintenance releases v1.38.3, v1.37.5, and v1.36.9. Affected deployments should upgrade to the corresponding patched release lines and review reloadable-feature reにr
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- envoyproxy_envoy_releases
- Record identifier
- de007cfe7e03216e68d8fb86fbfab726eb9abf6690b0691cbb655937918ca58b
- Enrichment time
- 2026-08-28T08:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.