Skip to content

v1.39.2

Choose a tag to compare

@publish-envoy publish-envoy released this 01 Oct 18:48

Summary of changes:

  • Security fixes:

    • CVE-2026-35189: tls: updated BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes.
  • Build/packaging:

    • Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
    • Moved Debian .changes and release checksum signing into the Bazel release assembly, with an audit of signing actions.
    • Refreshed the Ubuntu build and distroless Docker base images.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.2
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.2/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.2/version_history/v1.39/v1.39.2
Full changelog:
v1.39.1...v1.39.2

Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io