v1.39.0
2026-07-15T08:52:24Z•f4abf226c27bd84b8b877b2a02afe5913c0bd8bd40fe88717e7a22176a3b32e5
CVEauth-bypasscrashdenial-of-serviceenvoymemory-corruptionoauth2proxy-protocolrelease-notessecurity-fixvulnerabilityzstd
What happened
Multiple Envoy releases (v1.35.13 through v1.39.0) include security fixes addressing a broad set of vulnerabilities across filters and protocol handlers. Fixes cover crashes and use-after-free risks, authentication/authorization bypasses, an OAuth2 code verifier padding oracle, a zstd RLE “zip bomb” vector, PROXY Protocol v2 TLV spillover allowing attacker-controlled data to reach upstream, TLS SAN truncation with embedded NUL leading to auth bypass, stack overflow in JSON destructor, and other denial-of-service and stability issues. Users should upgrade to the patched releases listed in the (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- envoyproxy_envoy_releases
- Record identifier
- f4abf226c27bd84b8b877b2a02afe5913c0bd8bd40fe88717e7a22176a3b32e5
- Enrichment time
- 2026-07-15T08:52:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.