CuraDevOps

tag: Envoy · 4 items

2026-08-31 · Releases: envoy · source ↗ #envoy#security#service-mesh
  • Platform/SRE — Plan: v1.39.1 fixes multiple CVEs in Envoy’s HTTP/3 (UAF, CVE-2026-73512), HTTP/2 (process termination, CVE-2026-73513), and connection-handling paths — real data-plane exposure for any Istio, Contour, or Envoy-based ingress deployment. None are KEV-listed or confirmed exploited, so schedule patching this sprint rather than treating it as an emergency.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
2026-08-31 · Releases: envoy · source ↗ #envoy#security#service-proxy
  • Platform/SRE — Plan: Envoy is a common data-plane component in service meshes and ingress layers; this patch addresses a use-after-free in HTTP/3, process-termination bugs in HTTP/2, and multiple URL-normalization bypasses. No KEV listing or known active exploitation, so no hard deadline, but upgrade to v1.38.4 should be scheduled this sprint for any fleet running Envoy.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
2026-08-31 · Releases: envoy · source ↗ #envoy#security#service-mesh
  • Platform/SRE — Plan: Nine CVEs addressed including a UAF on HTTP/3, abnormal process termination on HTTP/2 trailers and ext_authz CONNECT requests, and a shared upstream connection-poisoning bug via HTTP upgrade — none are KEV-listed but the severity warrants scheduling an upgrade to v1.37.6 this sprint for any cluster running Envoy as ingress or data-plane proxy.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
2026-07-20 · Releases: envoy · source ↗ #envoy#security#service-mesh
  • Platform/SRE — Plan: v1.39.0 patches several CVEs across ext_authz, ext_proc, gRPC stats, and HTTP/2/HTTP/3 DoS vectors, but none are KEV-listed and EPSS is 0.00 — no hard deadline. Plan the upgrade this quarter, and validate the breaking TLS enforcement change and OpenTelemetry sampling behavior shift in staging before rolling to production.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: deprecation mentioned (no explicit date found) · breaking-change flagged · CVE-2026-47204 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47205 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47207 — CISA KEV: not listed, EPSS 0.00