Skip to content

Releases: dashpay/docker-envoy

v1.39.0-impr.1

Choose a tag to compare

@shumkov shumkov released this 26 Jul 12:50
f31829f

Bumps the base image from envoyproxy/envoy:v1.35.11 to envoyproxy/envoy:v1.39.0.

v1.35.11 predates Envoy's 2026-06-23 security batch of 15 advisories. v1.39.0 closes all of them, plus an HTTP/2 flood-protection bypass that was never backported to any patch line.

Denial of service / crash / memory exhaustion

  • HTTP/2 PRIORITY and WINDOW_UPDATE flood bypass (no CVE assigned, envoyproxy/envoy#45077): flood limits scaled with the cumulative count of streams ever opened, so an attacker churning streams inflated the budget without bound and never tripped the limit. Now scales with active streams and retires on close.
  • GHSA-p7c7-7c47-pwch (high): HTTP/3 QPACK blocked-decoding DoS
  • CVE-2026-48042 (high): stack overflow in destructor of highly nested JSON
  • CVE-2026-48044 (high): zstd RLE zip bomb, decompressor memory explosion
  • CVE-2026-47207: crash on multiple ext_proc responses in one gRPC message
  • CVE-2026-47221: null pointer deref in router internal redirects
  • CVE-2026-47204: grpc_stats segfault on Connect requests to direct_response
  • CVE-2026-48090: OAuth2 use-after-free on late async token completion
  • CVE-2026-48497: abnormal process termination in DNS UDP filter
  • CVE-2026-48706: heap buffer overflow in TcpStatsdSink on large stat names

Also fixed

Upgrade notes

Behavior changes inherited from Envoy 1.39.0 that are worth validating against your gateway configuration:

  • HeaderMatcher now evaluates repeated headers individually rather than comma-joined (revertible via envoy.reloadable_features.match_headers_individually)
  • TLS inspector rejects client TLS versions outside 1.0-1.3
  • enforce_rsa_key_usage is deprecated and always enforced
  • OpenTelemetry tracing honors Envoy's sampling decision, which may reduce exported spans

The python3 install, scripts/{hot-restarter.py,start_envoy.sh} and ENTRYPOINT are unchanged, so the SIGHUP zero-downtime hot restart is unaffected.

Full details in #4.

Dashpay Envoy v1.35.11-impr.1

Choose a tag to compare

@shumkov shumkov released this 04 Jun 07:32
38866d8

Bumps Envoy to v1.35.11 to patch GHSA-22m2-hvr2-xqc8 / CVE-2026-47774 (CVSS 7.5) — an unauthenticated HTTP/2 downstream memory-exhaustion DoS.

  • Base image: envoyproxy/envoy:v1.30.1 → v1.35.11
  • Hot-restart wrapper, scripts, and entrypoint unchanged

Built from #3. Publishes dashpay/envoy:1.35.11-impr.1 (+ 1.35.11-impr, 1.35-impr, 1-impr, latest-impr, latest).

Dashpay Envoy v1.30.2-impr.1

Choose a tag to compare

@shumkov shumkov released this 25 Apr 14:08
14e7fec

What's Changed

  • feat: enable log level configuration by @shumkov in #2

Full Changelog: v1.30.1...v1.30.2-impr.1

Dashpay Envoy v1.30.1

Choose a tag to compare

@shumkov shumkov released this 23 Apr 15:44
4c5c5cb

What's Changed

  • chore: update envoy to v1.30.1 by @shumkov in #1

New Contributors

Full Changelog: v1.22.11...v1.30.1

Dashpay Envoy v1.22.11

Choose a tag to compare

@strophy strophy released this 19 Jul 01:11
chore: pin envoy version