Envoy1.39.029d agosecuritybreaking - Multiple security vulnerabilities fixed including HTTP/2 cookie handling, HTTP/3 QPACK denial of service, and various authorization/authentication issues
- TLS now always enforces certificate keyUsage extension; client TLS versions are validated between 1.0-1.3
- New HTTP filters for weighted bandwidth sharing and dynamic module capabilities expanded with new extension points
- DNS cluster implementation unified and enabled by default; performance improvements for Prometheus scraping and large-scale stat operations
what breaks
TLS: enforce_rsa_key_usage is deprecated and ignored; Envoy now always enforces certificate keyUsage extension. TLS inspector: client TLS versions are validated and must be between TLS 1.0 and TLS 1.3. Intel DLB connection balancer (envoy.network.connection_balance.dlb) is disabled. HeaderMatcher behavior changed to evaluate header values individually instead of comma-joined. OpenTelemetry tracing may export fewer spans due to honoring request-entry sampling decisions. Build now requires Bazel 8 with WORKSPACE mode.
to upgrade
For OAuth2 security migration: enable oauth2_use_gcm_encryption, monitor oauth_legacy_cbc_decrypt counter, then disable oauth2_legacy_cbc_decrypt_compat. TLS inspector validation is revertible via envoy.reloadable_features.tls_inspector_enforce_client_tls_version. HeaderMatcher behavior is revertible via envoy.reloadable_features.match_headers_individually.
changelog ↗Envoy1.38.32mo agosecuritybreaking - Security fixes for 15 vulnerabilities including crashes in authz, router, and gRPC filters, authentication bypasses, request smuggling, and denial-of-service attacks
- Intel DLB connection balancer extension disabled due to source archive breakage
- TLS certificate compression via Brotli disabled by default for QUIC and TCP
what breaks
The Intel DLB connection balancer extension (envoy.network.connection_balance.dlb) is disabled and no longer available in builds. Users relying on this extension will need to find alternatives or apply local workarounds.
to upgrade
If using the Intel DLB connection balancer, see #45491 for local workarounds. Review the security fixes to determine if any affect your deployment.
changelog ↗- Fixed RTDS runtime guard override removal to properly restore default values when overrides are deleted
- Added optional HTTP/2 header statistics histograms (header count, byte size, cookie metrics) behind a feature flag
- Added configurable limit for reassembled cookie header size via new runtime guard
changelog ↗Envoyv1.38.12mo agosecuritybreaking - HTTP/2 streams are now reset if they exceed the configured maximum header list size, and uncompressed cookies now count towards header size limits to prevent HPACK cookie-bomb attacks
- Fixed timing side-channel vulnerability in OAuth2 HMAC verification and a crash in OAuth2 token cookie decryption
- Upstream transport failure reasons are no longer included in HTTP response bodies sent to clients (still available in access logs)
- Fixed a crash in the HTTP filter when streams exceeded the downstream write-buffer high watermark
what breaks
The upstream transport failure reason is no longer included in HTTP response bodies sent to downstream clients. Applications relying on this information in response bodies will need to use access logs instead. This can be reverted with envoy.reloadable_features.hide_transport_failure_reason_in_response_body.
to upgrade
If you depend on upstream transport failure reasons appearing in HTTP response bodies, set envoy.reloadable_features.hide_transport_failure_reason_in_response_body to false to revert the behavior. If you need to revert the HTTP/2 cookie counting behavior, set envoy.reloadable_features.http2_include_cookies_in_limits to false.
changelog ↗Envoy1.37.52mo agosecurity - Fixed 14 security vulnerabilities affecting authorization, gRPC processing, routing, OAuth2, DNS, HTTP/3, TLS, and other core components
- Disabled Intel DLB connection balancer extension due to source archive breakage
- Updated wasmtime dependency to resolve upstream security issue
changelog ↗- Fixed RTDS runtime guard override removal to properly restore default values when overrides are deleted
- Added optional HTTP/2 header statistics histograms (header count, byte size, cookie metrics) behind a feature flag
- Added configurable limit for reassembled cookie header size via new runtime guard
changelog ↗Envoy1.36.92mo agosecuritybreaking - Multiple upstream security vulnerabilities fixed including authorization crashes, OAuth2 bypass, TLS authentication bypass, HTTP/3 request smuggling, and buffer overflow issues
- Intel DLB connection balancer extension (envoy.network.connection_balance.dlb) disabled due to source archive breakage
what breaks
The Intel DLB connection balancer extension (envoy.network.connection_balance.dlb) is disabled and will not function. This affects users relying on this extension for connection balancing on Intel DLB-capable systems.
to upgrade
Users relying on the Intel DLB connection balancer should see issue #45491 for local workarounds.
changelog ↗- Fixed RTDS runtime guard override removal to properly restore default values when overrides are deleted
- Added optional HTTP/2 header statistics histograms (header count, byte size, cookie metrics) behind a feature flag
- Added configurable limit for reassembled cookie header size via new runtime guard
changelog ↗Envoy1.35.132mo agosecuritybreaking - Security fixes for 13 vulnerabilities including crashes, authentication bypasses, buffer overflows, and denial-of-service attacks across gRPC, OAuth2, HTTP/3, DNS, and TLS handling
- Intel DLB connection balancer extension (envoy.network.connection_balance.dlb) disabled due to source archive breakage
what breaks
The Intel DLB connection balancer extension is disabled and will not function. This affects deployments using the envoy.network.connection_balance.dlb extension for connection balancing.
to upgrade
If using the Intel DLB connection balancer extension, see #45491 for local workarounds.
changelog ↗- Fixed RTDS runtime guard override removal to properly restore default values when overrides are deleted
- Added optional HTTP/2 header statistics histograms (header count, byte size, cookie metrics) behind a feature flag
- Added configurable limit for reassembled cookie header size via new runtime guard
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗