v1.39.0

2026-07-15T08:52:24Zf4abf226c27bd84b8b877b2a02afe5913c0bd8bd40fe88717e7a22176a3b32e5
CVEauth-bypasscrashdenial-of-serviceenvoymemory-corruptionoauth2proxy-protocolrelease-notessecurity-fixvulnerabilityzstd

What happened

Multiple Envoy releases (v1.35.13 through v1.39.0) include security fixes addressing a broad set of vulnerabilities across filters and protocol handlers. Fixes cover crashes and use-after-free risks, authentication/authorization bypasses, an OAuth2 code verifier padding oracle, a zstd RLE “zip bomb” vector, PROXY Protocol v2 TLV spillover allowing attacker-controlled data to reach upstream, TLS SAN truncation with embedded NUL leading to auth bypass, stack overflow in JSON destructor, and other denial-of-service and stability issues. Users should upgrade to the patched releases listed in the (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
envoyproxy_envoy_releases
Record identifier
f4abf226c27bd84b8b877b2a02afe5913c0bd8bd40fe88717e7a22176a3b32e5
Enrichment time
2026-07-15T08:52:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · v1.39.0 · Baitaphish