Repository navigation
Releases: dashpay/docker-envoy
Release list
v1.39.0-impr.1
Bumps the base image from envoyproxy/envoy:v1.35.11 to envoyproxy/envoy:v1.39.0.
v1.35.11 predates Envoy's 2026-06-23 security batch of 15 advisories. v1.39.0 closes all of them, plus an HTTP/2 flood-protection bypass that was never backported to any patch line.
Denial of service / crash / memory exhaustion
- HTTP/2 PRIORITY and WINDOW_UPDATE flood bypass (no CVE assigned, envoyproxy/envoy#45077): flood limits scaled with the cumulative count of streams ever opened, so an attacker churning streams inflated the budget without bound and never tripped the limit. Now scales with active streams and retires on close.
- GHSA-p7c7-7c47-pwch (high): HTTP/3 QPACK blocked-decoding DoS
- CVE-2026-48042 (high): stack overflow in destructor of highly nested JSON
- CVE-2026-48044 (high): zstd RLE zip bomb, decompressor memory explosion
- CVE-2026-47207: crash on multiple ext_proc responses in one gRPC message
- CVE-2026-47221: null pointer deref in router internal redirects
- CVE-2026-47204: grpc_stats segfault on Connect requests to direct_response
- CVE-2026-48090: OAuth2 use-after-free on late async token completion
- CVE-2026-48497: abnormal process termination in DNS UDP filter
- CVE-2026-48706: heap buffer overflow in TcpStatsdSink on large stat names
Also fixed
- CVE-2026-48743 (high): HTTP/3 to HTTP/1 request smuggling
- CVE-2026-47778: embedded NUL TLS SAN truncation, auth bypass
- CVE-2026-47775: OAuth2 padding oracle, plus opt-in AES-256-GCM cookies
- CVE-2026-47692: PROXY protocol v2 skipped-TLV upstream spillover
- CVE-2026-47261: wasmtime bump, upstream dependency
Upgrade notes
Behavior changes inherited from Envoy 1.39.0 that are worth validating against your gateway configuration:
HeaderMatchernow evaluates repeated headers individually rather than comma-joined (revertible viaenvoy.reloadable_features.match_headers_individually)- TLS inspector rejects client TLS versions outside 1.0-1.3
enforce_rsa_key_usageis deprecated and always enforced- OpenTelemetry tracing honors Envoy's sampling decision, which may reduce exported spans
The python3 install, scripts/{hot-restarter.py,start_envoy.sh} and ENTRYPOINT are unchanged, so the SIGHUP zero-downtime hot restart is unaffected.
Full details in #4.
Dashpay Envoy v1.35.11-impr.1
Bumps Envoy to v1.35.11 to patch GHSA-22m2-hvr2-xqc8 / CVE-2026-47774 (CVSS 7.5) — an unauthenticated HTTP/2 downstream memory-exhaustion DoS.
- Base image:
envoyproxy/envoy:v1.30.1→v1.35.11 - Hot-restart wrapper, scripts, and entrypoint unchanged
Built from #3. Publishes dashpay/envoy:1.35.11-impr.1 (+ 1.35.11-impr, 1.35-impr, 1-impr, latest-impr, latest).
Dashpay Envoy v1.30.2-impr.1
What's Changed
Full Changelog: v1.30.1...v1.30.2-impr.1