v1.37.0
2026-03-04T20:41:29Z•ef37059877910ef8249029380ab48d5284274acd1d47f9f77f90569602964310
CVE-2025-0913CVE-2025-62504CVE-2025-64527CVE-2025-64763CVE-2025-66220c-arescertificate-matchingdenial-of-servicednsdynamic-modulesenvoyext_authzfiltersjwksjwtluareleaserequest-smugglingsdssecuritytls
What happened
Envoy v1.37.0 introduces major features (dynamic module expansion for network/listener/UDP/access-logger filters, streaming HTTP callouts, streaming body/header ABI, global module loading), many HTTP/protocol and observability enhancements, new filters (transform, MCP, geoip, Postgres Inspector), and security/authorization improvements (Proto API Scrubber production-ready, ext_authz enhancements, improved TLS cert validation messages, on‑demand SDS fetching). Several prior patch releases (v1.36.2–v1.36.4, v1.35.x, v1.34.x, v1.33.x) addressed multiple security vulnerabilities including: CVE-202
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- envoyproxy_envoy_releases
- Record identifier
- ef37059877910ef8249029380ab48d5284274acd1d47f9f77f90569602964310
- Enrichment time
- 2026-03-04T20:41:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.