v1.37.0

2026-03-04T20:41:29Zef37059877910ef8249029380ab48d5284274acd1d47f9f77f90569602964310
CVE-2025-0913CVE-2025-62504CVE-2025-64527CVE-2025-64763CVE-2025-66220c-arescertificate-matchingdenial-of-servicednsdynamic-modulesenvoyext_authzfiltersjwksjwtluareleaserequest-smugglingsdssecuritytls

What happened

Envoy v1.37.0 introduces major features (dynamic module expansion for network/listener/UDP/access-logger filters, streaming HTTP callouts, streaming body/header ABI, global module loading), many HTTP/protocol and observability enhancements, new filters (transform, MCP, geoip, Postgres Inspector), and security/authorization improvements (Proto API Scrubber production-ready, ext_authz enhancements, improved TLS cert validation messages, on‑demand SDS fetching). Several prior patch releases (v1.36.2–v1.36.4, v1.35.x, v1.34.x, v1.33.x) addressed multiple security vulnerabilities including: CVE-202

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
envoyproxy_envoy_releases
Record identifier
ef37059877910ef8249029380ab48d5284274acd1d47f9f77f90569602964310
Enrichment time
2026-03-04T20:41:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · v1.37.0 · Baitaphish