| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| checksums.txt.asc | 2026-08-26 | 1.5 kB | |
| envoy-1.38.4-linux-x86_64 | 2026-08-26 | 102.1 MB | |
| debs.tar.gz | 2026-08-26 | 1.0 GB | |
| envoy-1.38.4-linux-aarch_64 | 2026-08-26 | 98.7 MB | |
| envoy-contrib-1.38.4-linux-aarch_64 | 2026-08-26 | 152.6 MB | |
| envoy-contrib-1.38.4-linux-x86_64 | 2026-08-26 | 161.4 MB | |
| README.md | 2026-08-26 | 4.6 kB | |
| v1.38.4 source code.tar.gz | 2026-08-26 | 46.4 MB | |
| v1.38.4 source code.zip | 2026-08-26 | 54.0 MB | |
| Totals: 9 Items | 1.6 GB | 0 | |
repo: Release v1.38.4
Summary of changes:
- Security fixes:
- CVE-2026-73511: url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with
envoy.reloadable_features.strip_path_parameters_per_segment. - CVE-2026-73512: http3: UAF on a specifically timed sequence of HTTP/3 frames.
- CVE-2026-73513: http2: abnormal process termination on trailers received without the END_STREAM flag.
- CVE-2026-73546: admin: sanitize stat names before converting them to HTML. Guarded by
envoy.reloadable_features.sanitize_html_stats_names. - CVE-2026-73547: ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
- CVE-2026-73548: http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with
envoy.reloadable_features.http_pause_generic_upgrade_request_body. - CVE-2026-73549: quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
- CVE-2026-73550: http2: dropped
Hostheaders now count towards request header map size and count limits. Revert withenvoy.reloadable_features.http2_track_size_of_dropped_host_header. - CVE-2026-73551: url normalization: strip path parameters from dot and dotdot segments (
/.;,/..;) so canonicalization interprets them correctly. Applies only whennormalize_pathis enabled; revert withenvoy.reloadable_features.strip_dotdot_segments_with_parameters. - CVE-2026-73552: safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with
envoy.reloadable_features.re2_use_latin1_mode. - CVE-2026-73553: rbac: RBAC path matching now respects the route's
ignore_path_parameters_in_path_matching, preventing authz bypass via appended path parameters. Revert withenvoy.reloadable_features.rbac_respect_ignore_path_parameters. - CVE-2026-50572: ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
-
CVE-2026-48521: http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.
-
Bug fixes:
- http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via
addDecodedData()/addEncodedData()immediately before returningContinuewas silently dropped, corrupting large streamed bodies. Revert withenvoy.reloadable_features.filter_manager_forward_added_data_on_continue. - ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
- router: fixed a lifetime bug in dynamic forward proxy async host selection when the cluster is removed while lookup is still pending.
- tls: fixed a memory leak in the OpenSSL compatibility layer where
SSL_get0_peer_certificates()leaked anX509refcount per call, preventing certificates from being freed on connection close. - tls: fixed a bug where OpenSSL used glibc's allocator instead of tcmalloc, operating on a separate heap and making OpenSSL allocations invisible to tcmalloc heap profiling.
Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.4 Docs: https://www.envoyproxy.io/docs/envoy/v1.38.4/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.38.4/version_history/v1.38/v1.38.4 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.38.3...v1.38.4
Signed-off-by: Ryan Northey ryan@synca.io