Skip to content

v1.37.7

Choose a tag to compare

@publish-envoy publish-envoy released this 01 Oct 14:59

Summary of changes:

  • Security fixes:

    • CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. The BoringSSL FIPS build (--define boringssl=fips) does not receive this patch.
  • Build/packaging:

    • Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
    • Moved Debian .changes and release checksum signing into the Bazel release assembly, with an audit of signing actions.
    • Refreshed the Ubuntu build image.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.7
Docs:
https://www.envoyproxy.io/docs/envoy/v1.37.7/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.37.7/version_history/v1.37/v1.37.7
Full changelog:
v1.37.6...v1.37.7

Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io