| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| envoy-1.35.13-linux-aarch_64 | 2026-06-23 | 82.6 MB | |
| envoy-contrib-1.35.13-linux-aarch_64 | 2026-06-23 | 103.1 MB | |
| checksums.txt.asc | 2026-06-23 | 1.5 kB | |
| debs.tar.gz | 2026-06-23 | 765.1 MB | |
| envoy-1.35.13-linux-x86_64 | 2026-06-23 | 85.3 MB | |
| envoy-contrib-1.35.13-linux-x86_64 | 2026-06-23 | 111.5 MB | |
| README.md | 2026-06-23 | 2.9 kB | |
| v1.35.13 source code.tar.gz | 2026-06-23 | 25.0 MB | |
| v1.35.13 source code.zip | 2026-06-23 | 31.7 MB | |
| Totals: 9 Items | 1.2 GB | 0 | |
repo: Release v1.35.13
Summary of changes:
- Security fixes:
- CVE-2026-47207: ext_proc response in one gRPC message
- CVE-2026-47221: router internal redirects crash
- CVE-2026-47775: OAuth2 code verifier padding oracle
- CVE-2026-48044: zstd RLE zip bomb
- CVE-2026-47204: grpc_stats filter segfault on Connect protocol requests to direct_response routes
- CVE-2026-47692: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
- CVE-2026-47778: Embedded NUL in TLS SAN Truncation, Auth Bypass
- CVE-2026-48042: Stack overflow in destructor of highly nested JSON
- CVE-2026-48090: OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
- CVE-2026-48497: DNS filter abnormal process termination on long query name
- CVE-2026-48743: HTTP/3 headers-only request/response content-length not validated
- CVE-2026-48706: TcpStatsdSync buffer overflow with large stats name
-
GHSA-p7c7-7c47-pwch: Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding
-
Upstream security fixes:
-
CVE-2026-47261: wasm: bumped
com_github_wasmtimeto resolve CVE-2026-47261. -
Behavior changes:
- build: disabled the contrib extension
envoy.network.connection_balance.dlb(Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See https://github.com/envoyproxy/envoy/issues/45491 for local workarounds.
Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.13 Docs: https://www.envoyproxy.io/docs/envoy/v1.35.13/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.35.13/version_history/v1.35/v1.35.13 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.35.12...v1.35.13
Signed-off-by: Ryan Northey ryan@synca.io