Change8

Envoy

Backend & Infra

Cloud-native high-performance edge/middle/service proxy

Latest: v1.39.125 releases10 breaking changes1 common errorsView on GitHub

Release History

View all versions →
v1.39.1Breaking4 fixes
Aug 27, 2026

This release addresses multiple security vulnerabilities across various components including URL normalization, HTTP/3, HTTP/2, ext_authz, and QUIC. It also includes bug fixes for the filter manager, ext_proc, and TLS handling.

v1.38.4Breaking5 fixes
Aug 26, 2026

This release addresses multiple security vulnerabilities including issues with URL normalization, HTTP/3, HTTP/2, ext_authz, and QUIC. It also includes several bug fixes for filter management, ext_proc, dynamic forward proxy, and TLS memory leaks.

v1.37.6Breaking4 fixes
Aug 26, 2026

This release addresses multiple security vulnerabilities including issues with URL normalization, HTTP/3, HTTP/2, ext_authz, and QUIC. It also includes several bug fixes for the http filter manager, ext_proc filter, and router.

v1.36.10Breaking4 fixes
Aug 26, 2026

This release addresses multiple security vulnerabilities across various components including URL normalization, HTTP/3, HTTP/2, admin, ext_authz, and QUIC. It also includes several bug fixes for filter management, ext_proc, and router functionalities.

v1.39.0
Jul 14, 2026
v1.38.3Breaking16 fixes
Jun 23, 2026

This release primarily focuses on numerous security fixes across various components, including Authz, HTTP/3, TLS, and various filters. It also disables the Intel DLB connection balancer extension by default.

v1.37.5Breaking16 fixes
Jun 23, 2026

Release v1.37.5 focuses heavily on security, addressing numerous CVEs across various components including Authz, HTTP/3, OAuth2, and Zstd decompression. Additionally, the Intel DLB connection balancer extension was disabled due to upstream source archive issues.

v1.36.9Breaking15 fixes
Jun 23, 2026

Release v1.36.9 primarily incorporates numerous upstream security fixes from Envoy, addressing vulnerabilities ranging from crashes and buffer overflows to protocol smuggling and DoS risks. Additionally, the Intel DLB connection balancer extension has been disabled due to upstream source breakage.

v1.35.13Breaking14 fixes
Jun 23, 2026

This release primarily focuses on addressing numerous critical security vulnerabilities across various components, including HTTP/3, OAuth2, and various filters. Additionally, the Intel DLB connection balancer extension has been disabled due to upstream issues.

v1.38.21 fix2 features
Jun 10, 2026

This patch release fixes a bug in RTDS runtime guard handling and introduces new opt-in features for monitoring HTTP/2 header statistics and limiting cookie header size.

v1.37.41 fix2 features
Jun 10, 2026

This patch fixes a bug related to RTDS runtime guard override removal and introduces new opt-in features for monitoring HTTP/2 header statistics and limiting cookie header size.

v1.36.81 fix2 features
Jun 10, 2026

This release fixes a bug related to RTDS runtime guard override removal and introduces new opt-in features for monitoring HTTP/2 header statistics and limiting cookie header size.

v1.35.121 fix2 features
Jun 10, 2026

This patch fixes a bug related to RTDS runtime guard overrides and introduces new opt-in features for monitoring HTTP/2 header statistics and limiting cookie header size.

v1.38.1Breaking5 fixes1 feature
Jun 4, 2026

This release focuses heavily on security fixes, addressing vulnerabilities in HTTP/2 header limits, HMAC verification, and AES-CBC decryption. It also includes several bug fixes and minor behavior changes regarding upstream failure reasons and load balancer rebuild coalescing.

v1.37.35 fixes
Jun 4, 2026

Release v1.37.3 includes several security fixes related to HTTP/2 header limits, HMAC verification, and AES-CBC decryption, alongside a fix for a load report shutdown race condition.

v1.36.75 fixes
Jun 4, 2026

This release focuses on security fixes, addressing vulnerabilities in HTTP/2 header limits and OAuth2 HMAC verification, alongside a fix for a load report shutdown race condition.

v1.35.115 fixes2 features
Jun 3, 2026

This release focuses heavily on security fixes, addressing vulnerabilities in HTTP/2 header limits, HMAC verification, and AES-CBC decryption. It also introduces new features for periodic metric eviction and limiting stats scope size.

v1.38.0Breaking5 fixes48 features
Apr 23, 2026

This release introduces extensive new capabilities for dynamic module extensibility, significant enhancements to the MCP and A2A protocols, and security hardening across TLS and authorization components. Several configuration defaults have been tightened, notably around RSA key usage enforcement.

v1.37.23 fixes
Apr 10, 2026

This patch release fixes several critical bugs, including crashes related to listener removal and request buffering issues, alongside updates to Docker images and statistics.

v1.36.62 fixes
Apr 10, 2026

This patch release fixes critical bugs related to dynamic module filtering and internal redirect buffering, and updates the Docker release images.

v1.35.101 fix
Apr 10, 2026

This patch release primarily focuses on updating and fixing issues found in the Docker release images for version 1.35.10.

v1.34.141 fix
Apr 10, 2026

This release primarily focuses on updating and fixing issues within the Docker release images for Envoy version v1.34.14.

v1.37.111 fixes1 feature
Mar 11, 2026

This release focuses heavily on security fixes across multiple components, including ratelimit, rbac, json, and http handling. It also includes several bug fixes for OAuth2, ext_proc, ext_authz, and access logging.

v1.36.56 fixes
Mar 11, 2026

This release focuses primarily on security fixes addressing multiple CVEs related to crashes, header bypasses, and memory corruption. It also includes a bug fix for OAuth2 refresh requests.

v1.35.95 fixes
Mar 10, 2026

This release focuses primarily on security fixes addressing various vulnerabilities, including issues in rbac, IPv6 handling, JSON parsing, and HTTP decoding. It also includes a fix for OAuth2 host rewriting and dependency updates.

Common Errors

Related Backend & Infra Packages

Subscribe to Updates

Get notified when new versions are released

RSS Feed