Last 7 days
0
Features: 0
Changes: 0
Fixes: 0
Deprecations: 0
High-performance edge and service proxy for cloud-native applications.
Latest Envoy changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Envoy release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
0
0
13
52
Build system upgraded to Bazel 8 (breaking) with workspace mode changes and Intel DLB balancer disabled; new dynamic module extension points and Rust SDK enhancements added.
Patched numerous CVEs affecting authz, gRPC, OAuth2, TLS, HTTP/3, and other components, addressing crashes, memory safety, and certificate handling bugs.
Multiple security fixes targeting a range of CVEs, including authz crashes, OAuth2 vulnerabilities, TLS SAN bypass, and HTTP/3 denial‑of‑service issues.
Applied upstream security patches for numerous CVEs covering authz crashes, OAuth2 padding oracle, TLS SAN bypass, HTTP/3 QPACK DoS, and other vulnerabilities.
Fixed multiple critical CVEs affecting gRPC, OAuth2, TLS, JSON, DNS, HTTP/3 and other components
Fixed runtime guard override removal bug so deleting an override restores the default guard value
Fixed RTDS runtime guard override removal so deleting an override restores the default guard value.
Fixed RTDS runtime guard override removal bug, restoring default guard value when an override is deleted.
Fixed RTDS runtime guard override removal to correctly restore the default guard value.
HTTP/2 security updates: streams reset on header size violations, cookies count toward header limits, and nghttp2 CVE‑2026‑27135 patch applied.
Reset HTTP/2 streams that exceed max header list size and count uncompressed cookies toward header limits, mitigating HPACK cookie bomb and applying CVE‑2026‑47774 and CVE‑2026‑27135 patches.
HTTP/2 streams now reset when exceeding max header list size and cookies count toward header limits, mitigating HPACK cookie bomb attacks.
Fixed multiple HTTP/2 security issues (CVE‑2026‑47774, CVE‑2026‑27135) and hardened OAuth2 HMAC verification and token cookie handling
Breaking: TCP proxy now requires max early data bytes for non‑IMMEDIATE upstream connect modes; BoringSSL/FIPS flag removed; RSA key‑usage enforcement defaults to true and will be removed in a future release.
Fixed crash on listener removal when using a process‑level access log rate limiter
Fix dynamic module filters that could send incomplete request/response bodies when adjacent filters performed buffering
Updated and fixed Docker release images for Envoy v1.35.10.
Fix and update Docker release images for v1.34.14
Multiple security fixes address CVE‑2026‑26330, 26308, 26310, 26309 and 26311 (rate‑limit crash, RBAC header bypass, IPv6 address handling, JSON off‑by‑one write, HTTP decode after reset).
Security fixes for CVE-2026-26330, CVE-2026-26308, CVE-2026-26310, CVE-2026-26309, and CVE-2026-26311, addressing ratelimit crashes, RBAC header bypass, IPv6 address handling, JSON off‑by‑one write, and blocked HTTP decode after downstre...
Patched multiple CVE‑2026 security issues: multivalue header RBAC bypass, IPv6 address crash, JSON off‑by‑one write, and HTTP decode after downstream reset.
Patched multiple security CVEs (multivalue header RBAC bypass, IPv6 address crash, JSON OOB write, downstream reset handling)
Added many new filters (network, listener, UDP, access logger, transform, MCP, geoip, Postgres) plus streaming HTTP callouts, ABI enhancements, and global module loading.
Fix c‑ares use‑after‑free CVE‑2025‑0913 (potential DNS crash).
Resolved c‑ares CVE‑2025‑0913 (use‑after‑free) preventing crashes when DNS is compromised
Resolved c‑ares CVE‑2025‑0913 (use‑after‑free) that could crash Envoy in certain cloud setups
Fixed c-ares CVE‑2025‑0913 (use‑after‑free) that could crash Envoy via malicious DNS
Fixed CVE‑2025‑64527: Envoy crash when JWT authentication uses remote JWKS fetching
Fixed CVE‑2025‑64527 causing Envoy crashes when JWT authentication uses remote JWKS fetching.
Patched CVE-2025-64527 preventing Envoy crashes when JWT authentication uses remote JWKS fetching.
Fix CVE‑2025‑64527: Envoy crash when JWT authentication uses remote JWKS fetching.
Patched CVE‑2025‑62504, fixing a crash triggered by large response bodies in Lua filters.
Fix CVE‑2025‑62504: prevent crashes when Lua filters process very large response bodies.
Fix CVE‑2025‑62504 causing crashes when Lua filters process large response bodies
- Fixed CVE‑2025‑62504 causing crashes in Lua filters with large response bodies
Fixed CVE‑2025‑62409 by patching a crash in the TCP connection pool.
Patched CVE‑2025‑62409 by fixing a crash in the TCP connection pool.
Fix crash in TCP connection pool (CVE‑2025‑62409)
Fix CVE‑2025‑62409 by addressing a crash in the TCP connection pool.
- Updated HTTP/2 defaults (max streams 1024, reduced window sizes) and added HTTP/1.1 CONNECT proxy support, header removal patterns, and per‑route compressor overrides.
Updated dependencies to address multiple CVEs (fips/go, LuaJIT, Kafka)
Addressed multiple CVEs across dependencies (curl, gRPC, luajit, kafka).
Resolve multiple CVEs (curl, gRPC, luajit, kafka)
Updated dependencies to resolve multiple CVEs across curl, gRPC, kafka, and wasmtime libraries.
Fixed Docker distroless images to ensure they run as non‑root.
Corrected Docker distroless images to enforce non‑root user execution.
Fix Docker distroless images to ensure they run as a non‑root user
Fixed Docker distroless images to ensure they run as a non‑root user.
Fixed OAuth cookie vulnerability (CVE‑2025‑55162).
Fixed OAuth cookie vulnerability (CVE‑2025‑55162).
Patched OAuth cookie vulnerability (CVE‑2025‑55162).
Patched OAuth cookie vulnerability (CVE‑2025‑55162).
Refresh base images to latest Ubuntu and distroless versions.
Update Ubuntu and distroless base images for Envoy releases.
Update Ubuntu and distroless base images
Updated Ubuntu and distroless base images for the release.
Updated V8 and Wasmtime in the Wasm extension to resolve CVEs
Update Wasm V8 and Wasmtime to address CVEs
Updated Wasm V8 runtime to address multiple CVEs.
Upgraded to C++20 and unified clang/gcc toolchains while removing grpc credentials/aws iam extension and contrib squash filter (breaking change).
Fixed TLS connection property caching bug that broke network RBAC filters
Fixed TLS connection property caching that broke network RBAC filters
Fixed division‑by‑zero bug in Dynatrace sampling controller (observability).
Fixed division‑by‑zero bug in Dynatrace sampling controller (observability).
Updated container images to address glibc security vulnerabilities
Update container images to address glibc vulnerabilities
Updated Envoy container images to address glibc vulnerabilities
Update container images to address glibc vulnerabilities
Patched CVE‑2025‑46821 addressing RBAC URI template permission bypass.
Fix for CVE‑2025‑46821 addressing RBAC URI‑template permission bypass
Patched CVE-2025-46821 to prevent RBAC URI template permission bypass.
Fix CVE‑2025‑46821 allowing RBAC URI template permission bypass
Security fixes address CVE-2025-30157 and CVE-2025-31498, including a c-ares upgrade and correcting local reply handling.
Upgraded Envoy Docker images to version v1.33.2
Updated Envoy Docker images to version v1.32.5
Update Docker images to Envoy v1.31.7 with container fixes
Update Docker images to v1.30.11
Fixed CVE‑2025‑30157: corrected local replies being sent to the ext proc server
Fixed CVE‑2025‑30157 where local replies were mistakenly sent to the external processing server.
Fix CVE‑2025‑30157 by correcting local reply routing, preventing them from being sent to the external processing server.
Fix CVE‑2025‑30157: local replies were incorrectly sent to the ext_proc server.
- Security updates: CVE‑2024‑25629 c‑ares out‑of‑bounds read fix; RFC1918 addresses no longer treated as internal; added P‑384/P‑521 curves, improved SNI/SAN validation, and Signed Double Submit Cookie pattern.
Fix CVE‑2024‑53269: Validate additional addresses are IPs in Happy Eyeballs to prevent sorting crash.
Fix CVE‑2024‑53269: validate additional addresses are IPs in Happy Eyeballs to prevent sorting crashes
Fix CVE-2024-53269: Validate that additional addresses are IPs in Happy Eyeballs to prevent crashes.
Fixed CVE‑2024‑53270: prevented crashes in HTTP/1 when overload is sent and the request is reset beforehand.
Fixed minor bugs across the release
Fixed minor bugs across the codebase
Fixed minor bugs across the release
Fixed multiple minor bugs across the codebase.
Updated CI pipelines and release container configurations
Fixed a minor tracing bug
Fixed a minor tracing bug
Fixed a minor tracing bug.
- Added many new features: max response header size config, per‑downstream connection‑pool flag, DNS jitter field, dynamic metadata matcher, trusted CIDR list for X‑Forwarded‑For, QUIC certificate compression, CPU utilization monitor, ex...
Fixed CVE-2024-45807 to CVE-2024-45810, resolving crashes, log injection, header manipulation, JWT filter, and async client LocalReply issues.
Patched CVE‑2024‑45808, CVE‑2024‑45806, CVE‑2024‑45809, and CVE‑2024‑45810 addressing log injection, header manipulation, JWT filter crash, and LocalReply crash issues.
Fixed multiple CVE‑2024‑45808/45806/45809/45810 issues: log injection, header manipulation, JWT filter crash, and Envoy crash in HTTP async client
Patched CVE‑2024‑45808 to stop malicious log injection via access logs
Update curl library to address CVE‑2024‑7264 vulnerability
Updated curl library to remediate CVE‑2024‑7264
Updated curl library to address CVE‑2024‑7264
Update curl library to fix CVE‑2024‑7264
Added extensive extensibility features: new access‑log operators, ext‑authz header block‑list and decoder‑mutation controls, and external processor support for observability mode and route‑cache actions.
Fix CVE‑2024‑39305: correct handling of additional cookie attributes so they are sent to clients.
Fix CVE‑2024‑39305: correct handling of additional cookie attributes so they are sent to clients
Fix CVE‑2024‑39305 vulnerability in Envoy.
Fix CVE‑2024‑39305 by correctly sending additional cookie attributes to clients.
Updated Datadog library version to fix a crashing bug in earlier versions.
Bumped the datadog library version to fix a crashing bug in earlier releases.
Patched multiple CVE‑2024 security issues including use‑after‑free crashes, OOM risks, and infinite Brotli decompression loops.
Fixed multiple CVE‑2024 security vulnerabilities including use‑after‑free, JSON exception, and OOM issues in EnvoyQuicServerStream and HTTP async client.
Fix multiple security vulnerabilities including use‑after‑free, uncaught JSON exception crashes, OOM in HTTP async client, and infinite Brotli decompression loop.
Patched multiple CVE‑2024 vulnerabilities (use‑after‑free, OOM, crashes, and improper HTTP upgrade handling).
Fixed potential TLS/SNI auto‑SNI crash addressing CVE‑2024‑32475.
Patched potential TLS/SNI auto‑SNI crash (CVE‑2024‑32475).
Patched a TLS/SNI auto‑SNI crash vulnerability (CVE‑2024‑32475).
Fix for potential TLS/SNI crash addressing CVE‑2024‑32475.
Removed the Swift/C++ interop layer and added CONNECT proxy, log level support, and QUIC socket buffer/idle timeout tweaks in Envoy Mobile.
Patch nghttp2 to address CVE‑2024‑30255, improving security.
Patch nghttp2 to address CVE‑2024‑30255
Update nghttp2 library to fix CVE‑2024‑30255
Patch nghttp2 to address CVE‑2024‑30255
Reverted the default HTTP/2 codec to nghttp2 to resolve reported issues (e.g., #32611, #32401).
Patched multiple security vulnerabilities (CVE‑2024‑23322, CVE‑2024‑23323, CVE‑2024‑23324, CVE‑2024‑23325, CVE‑2024‑23327).
Patched CVE‑2024‑23324, CVE‑2024‑23325, CVE‑2024‑23322, CVE‑2024‑23323, and CVE‑2024‑23327.
Patched multiple CVE-2024-233xx security vulnerabilities (CVE-2024-23322, 23323, 23324, 23325, 23327)
Fixed multiple CVE‑2024 security vulnerabilities (23322, 23323, 23324, 23325, 23327).
Added new extensions and configurability: HTTP basic auth, ext‑authz route metadata, per‑route body buffering, CEL support in ext‑proc, and configurable HTTP status for global rate‑limit failures.
Switched to BalsaParser for HTTP/1.1, hardened TLS inspector, added HTTP Capsule protocol and TCP RST handling on Linux.
Fixed crash caused by processing deferred streams when `http.max_requests_per_io_cycle` is greater than 1.
Fixed crash when processing deferred streams with `http.max_requests_per_io_cycle` greater than 1.
Fixed a crash that occurred when processing deferred streams with `http.max_requests_per_io_cycle` set higher than 1.
Fixed a crash bug when processing deferred streams with `http.max_requests_per_io_cycle` set above 1.
Fixed CVE‑2023‑44487 vulnerability in Envoy
Resolve CVE‑2023‑44487 security vulnerability
Patched CVE-2023-44487 security vulnerability
Resolve CVE‑2023‑44487 affecting Envoy
Introduce a new Golang network filter, CONNECT‑UDP support, and CEL‑based access‑log formatting/universal matcher expressions.
Resolved Envoy CVE‑2023‑35945 with a security fix
Updated Wasmtime to 9.0.3, fixing CVE‑2023‑30624
Updated Wasmtime to 9.0.3, fixing CVE‑2023‑30624
Updated Wasmtime to 9.0.3, fixing CVE‑2023‑30624.
Updated Wasmtime dependency to version 9.0.3, addressing CVE-2023-30624.
Envoy v1.26.1 released with updated Docker images and documentation.
Published Docker images for Envoy v1.25.6.
Release v1.24.7 is now available.
Release v1.23.9 publishes new Docker images for Envoy 1.23.
Release v1.26.0 of Envoy.
Fix multiple Envoy CVEs (2023‑27487, 2023‑27491, 2023‑27492, 2023‑27493, 2023‑27488, 2023‑27496)
Patch multiple Envoy CVEs (2023‑27487, 27491, 27492, 27493, 27488, 27496)
Fixes multiple Envoy CVEs (2023-27487, 2023-27491, 2023-27492, 2023-27493, 2023-27488, 2023-27496)
Patch multiple Envoy CVEs (2023-27487, 27491, 27492, 27493, 27488, 27496)
Update Wasmtime dependency to version 6.0.1.
Updated Wasmtime dependency to version 6.0.1.
Upgrade Wasmtime dependency to version 6.0.1, addressing CVE‑2023‑26489 and CVE‑2023‑27477.
Updated Wasmtime dependency to version 6.0.1, fixing CVE-2023-26489 and CVE-2023-27477.
Version v1.22.5 details are available in the Envoy documentation link provided.
Minor release v1.22.4 for Envoy
Fix several stability issues across HTTP filters and the load balancer
Fixed a regression causing crashes in HTTP/2 stream cleanup and memory leaks in the TCP proxy filter.
Fixed several critical bugs affecting HTTP/2 stream handling, DNS resolver stability, and memory leaks in stats collection.
Added experimental HTTP/3 (QUIC) support with new listener and transport socket extensions.
Fixed security issue with the X-Envoy-Original-Dst-Host header
Initial open-source release of the project (v1.0.0).