<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Envoy on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/envoy/</link><description>Recent content in Envoy on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 18:45:38 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/envoy/index.xml" rel="self" type="application/rss+xml"/><item><title>Envoy v1.37.6 patches nine CVEs including UAF and HTTP/2 crash bugs</title><link>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-37-6/</link><pubDate>Mon, 31 Aug 2026 18:45:38 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-37-6/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Nine CVEs addressed including a UAF on HTTP/3, abnormal process termination on HTTP/2 trailers and ext_authz CONNECT requests, and a shared upstream connection-poisoning bug via HTTP upgrade — none are KEV-listed but the severity warrants scheduling an upgrade to v1.37.6 this sprint for any cluster running Envoy as ingress or data-plane proxy.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a&lt;/li>
&lt;/ul></description></item><item><title>Envoy v1.38.4 patches 9+ CVEs including HTTP/3 UAF and HTTP/2 crash bugs</title><link>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-38-4/</link><pubDate>Mon, 31 Aug 2026 18:45:38 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-38-4/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Envoy is a common data-plane component in service meshes and ingress layers; this patch addresses a use-after-free in HTTP/3, process-termination bugs in HTTP/2, and multiple URL-normalization bypasses. No KEV listing or known active exploitation, so no hard deadline, but upgrade to v1.38.4 should be scheduled this sprint for any fleet running Envoy.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a&lt;/li>
&lt;/ul></description></item><item><title>Envoy v1.39.1 patches multiple CVEs including HTTP/3 UAF and HTTP/2 crash</title><link>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-39-1/</link><pubDate>Mon, 31 Aug 2026 18:45:38 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-39-1/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> v1.39.1 fixes multiple CVEs in Envoy&amp;rsquo;s HTTP/3 (UAF, CVE-2026-73512), HTTP/2 (process termination, CVE-2026-73513), and connection-handling paths — real data-plane exposure for any Istio, Contour, or Envoy-based ingress deployment. None are KEV-listed or confirmed exploited, so schedule patching this sprint rather than treating it as an emergency.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a&lt;/li>
&lt;/ul></description></item><item><title>Envoy v1.39.0: multiple CVE fixes, TLS and HTTP/2/3 breaking changes</title><link>https://curadevops.metacog.co.kr/insights/2026-07-20-v1-39-0/</link><pubDate>Mon, 20 Jul 2026 14:01:18 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-20-v1-39-0/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> v1.39.0 patches several CVEs across ext_authz, ext_proc, gRPC stats, and HTTP/2/HTTP/3 DoS vectors, but none are KEV-listed and EPSS is 0.00 — no hard deadline. Plan the upgrade this quarter, and validate the breaking TLS enforcement change and OpenTelemetry sampling behavior shift in staging before rolling to production.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> deprecation mentioned (no explicit date found) · breaking-change flagged · CVE-2026-47204 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47205 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47207 — CISA KEV: not listed, EPSS 0.00&lt;/li>
&lt;/ul></description></item></channel></rss>