v1.39.1

2026-08-28T08:52:17Zde007cfe7e03216e68d8fb86fbfab726eb9abf6690b0691cbb655937918ca58b
CVE-2026-47204CVE-2026-47205CVE-2026-47207CVE-2026-47220CVE-2026-47221CVE-2026-47692CVE-2026-47774CVE-2026-47775CVE-2026-47778CVE-2026-48042CVE-2026-48044CVE-2026-48090CVE-2026-48743CVE-2026-73511CVE-2026-73512CVE-2026-73513CVE-2026-73546CVE-2026-73547CVE-2026-73548CVE-2026-73549CVE-2026-73550EnvoyEnvoy ProxyHTML injectionHTTP/1.1HTTP/2HTTP/3QUICURL normalizationadmin interfaceconnection poisoningcrashdenial of serviceext_authzprotocol parsingrequest smugglingsecurity releaseuse-after-free

What happened

Envoy Proxy security releases v1.39.1, v1.38.4, v1.37.6, and v1.36.10 address multiple vulnerabilities across HTTP/1, HTTP/2, HTTP/3, QUIC, URL normalization, ext_authz, and the admin interface. Issues include use-after-free, crashes or abnormal termination, request smuggling and connection poisoning, HTML injection, and protocol/resource-limit handling weaknesses. The document also references earlier security fixes in v1.39.0 and maintenance releases v1.38.3, v1.37.5, and v1.36.9. Affected deployments should upgrade to the corresponding patched release lines and review reloadable-feature reにr

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
envoyproxy_envoy_releases
Record identifier
de007cfe7e03216e68d8fb86fbfab726eb9abf6690b0691cbb655937918ca58b
Enrichment time
2026-08-28T08:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · v1.39.1 · Baitaphish