Envoy
Backend & InfraCloud-native high-performance edge/middle/service proxy
Release History
View all versions →v1.39.1Breaking4 fixesThis release addresses multiple security vulnerabilities across various components including URL normalization, HTTP/3, HTTP/2, ext_authz, and QUIC. It also includes bug fixes for the filter manager, ext_proc, and TLS handling.
v1.38.4Breaking5 fixesThis release addresses multiple security vulnerabilities including issues with URL normalization, HTTP/3, HTTP/2, ext_authz, and QUIC. It also includes several bug fixes for filter management, ext_proc, dynamic forward proxy, and TLS memory leaks.
v1.37.6Breaking4 fixesThis release addresses multiple security vulnerabilities including issues with URL normalization, HTTP/3, HTTP/2, ext_authz, and QUIC. It also includes several bug fixes for the http filter manager, ext_proc filter, and router.
v1.36.10Breaking4 fixesThis release addresses multiple security vulnerabilities across various components including URL normalization, HTTP/3, HTTP/2, admin, ext_authz, and QUIC. It also includes several bug fixes for filter management, ext_proc, and router functionalities.
v1.39.0v1.38.3Breaking16 fixesThis release primarily focuses on numerous security fixes across various components, including Authz, HTTP/3, TLS, and various filters. It also disables the Intel DLB connection balancer extension by default.
v1.37.5Breaking16 fixesRelease v1.37.5 focuses heavily on security, addressing numerous CVEs across various components including Authz, HTTP/3, OAuth2, and Zstd decompression. Additionally, the Intel DLB connection balancer extension was disabled due to upstream source archive issues.
v1.36.9Breaking15 fixesRelease v1.36.9 primarily incorporates numerous upstream security fixes from Envoy, addressing vulnerabilities ranging from crashes and buffer overflows to protocol smuggling and DoS risks. Additionally, the Intel DLB connection balancer extension has been disabled due to upstream source breakage.
v1.35.13Breaking14 fixesThis release primarily focuses on addressing numerous critical security vulnerabilities across various components, including HTTP/3, OAuth2, and various filters. Additionally, the Intel DLB connection balancer extension has been disabled due to upstream issues.
v1.38.21 fix2 featuresThis patch release fixes a bug in RTDS runtime guard handling and introduces new opt-in features for monitoring HTTP/2 header statistics and limiting cookie header size.
v1.37.41 fix2 featuresThis patch fixes a bug related to RTDS runtime guard override removal and introduces new opt-in features for monitoring HTTP/2 header statistics and limiting cookie header size.
v1.36.81 fix2 featuresThis release fixes a bug related to RTDS runtime guard override removal and introduces new opt-in features for monitoring HTTP/2 header statistics and limiting cookie header size.
v1.35.121 fix2 featuresThis patch fixes a bug related to RTDS runtime guard overrides and introduces new opt-in features for monitoring HTTP/2 header statistics and limiting cookie header size.
v1.38.1Breaking5 fixes1 featureThis release focuses heavily on security fixes, addressing vulnerabilities in HTTP/2 header limits, HMAC verification, and AES-CBC decryption. It also includes several bug fixes and minor behavior changes regarding upstream failure reasons and load balancer rebuild coalescing.
v1.37.35 fixesRelease v1.37.3 includes several security fixes related to HTTP/2 header limits, HMAC verification, and AES-CBC decryption, alongside a fix for a load report shutdown race condition.
v1.36.75 fixesThis release focuses on security fixes, addressing vulnerabilities in HTTP/2 header limits and OAuth2 HMAC verification, alongside a fix for a load report shutdown race condition.
v1.35.115 fixes2 featuresThis release focuses heavily on security fixes, addressing vulnerabilities in HTTP/2 header limits, HMAC verification, and AES-CBC decryption. It also introduces new features for periodic metric eviction and limiting stats scope size.
v1.38.0Breaking5 fixes48 featuresThis release introduces extensive new capabilities for dynamic module extensibility, significant enhancements to the MCP and A2A protocols, and security hardening across TLS and authorization components. Several configuration defaults have been tightened, notably around RSA key usage enforcement.
v1.37.23 fixesThis patch release fixes several critical bugs, including crashes related to listener removal and request buffering issues, alongside updates to Docker images and statistics.
v1.36.62 fixesThis patch release fixes critical bugs related to dynamic module filtering and internal redirect buffering, and updates the Docker release images.
v1.35.101 fixThis patch release primarily focuses on updating and fixing issues found in the Docker release images for version 1.35.10.
v1.34.141 fixThis release primarily focuses on updating and fixing issues within the Docker release images for Envoy version v1.34.14.
v1.37.111 fixes1 featureThis release focuses heavily on security fixes across multiple components, including ratelimit, rbac, json, and http handling. It also includes several bug fixes for OAuth2, ext_proc, ext_authz, and access logging.
v1.36.56 fixesThis release focuses primarily on security fixes addressing multiple CVEs related to crashes, header bypasses, and memory corruption. It also includes a bug fix for OAuth2 refresh requests.
v1.35.95 fixesThis release focuses primarily on security fixes addressing various vulnerabilities, including issues in rbac, IPv6 handling, JSON parsing, and HTTP decoding. It also includes a fix for OAuth2 host rewriting and dependency updates.
Common Errors
Related Backend & Infra Packages
Production-Grade Container Scheduling and Management
Node.js JavaScript runtime ✨🐢🚀✨
Promise based HTTP client for the browser and node.js
A modern runtime for JavaScript and TypeScript.
Deliver web apps with confidence 🚀
Incredibly fast JavaScript runtime, bundler, test runner, and package manager – all in one
Subscribe to Updates
Get notified when new versions are released