CuraDevOps

tag: Service-Mesh · 6 items

2026-08-31 · Releases: istio · source ↗ #service-mesh#istio#kubernetes
  • Platform/SRE — Plan: A new Istio minor release is always a candidate for upgrade planning — review the full release notes for breaking changes, API removals, or deprecations before scheduling a mesh upgrade this quarter.
  • CI/CD — Skip
  • Leader — Skip
2026-08-31 · Releases: envoy · source ↗ #envoy#security#service-mesh
  • Platform/SRE — Plan: v1.39.1 fixes multiple CVEs in Envoy’s HTTP/3 (UAF, CVE-2026-73512), HTTP/2 (process termination, CVE-2026-73513), and connection-handling paths — real data-plane exposure for any Istio, Contour, or Envoy-based ingress deployment. None are KEV-listed or confirmed exploited, so schedule patching this sprint rather than treating it as an emergency.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
2026-08-31 · Releases: envoy · source ↗ #envoy#security#service-mesh
  • Platform/SRE — Plan: Nine CVEs addressed including a UAF on HTTP/3, abnormal process termination on HTTP/2 trailers and ext_authz CONNECT requests, and a shared upstream connection-poisoning bug via HTTP upgrade — none are KEV-listed but the severity warrants scheduling an upgrade to v1.37.6 this sprint for any cluster running Envoy as ingress or data-plane proxy.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
  • Platform/SRE — Learn: Addresses a real gotcha in Istio+Kiali+Prometheus setups where request metrics get double-counted; worth reading if you operate a service mesh and are debugging unexpected metric values.
  • CI/CD — Skip
  • Leader — Skip
2026-07-23 · HashiCorp Blog · source ↗ #service-mesh#consul#networking
  • Platform/SRE — Learn: Useful capability if you run Consul service mesh — one identity with multiple named ports reduces catalog sprawl. No deadline or GA-vs-pre-GA status confirmed in signals, so evaluate when scoping next Consul adoption work.
  • CI/CD — Skip
  • Leader — Skip
2026-07-20 · Releases: envoy · source ↗ #envoy#security#service-mesh
  • Platform/SRE — Plan: v1.39.0 patches several CVEs across ext_authz, ext_proc, gRPC stats, and HTTP/2/HTTP/3 DoS vectors, but none are KEV-listed and EPSS is 0.00 — no hard deadline. Plan the upgrade this quarter, and validate the breaking TLS enforcement change and OpenTelemetry sampling behavior shift in staging before rolling to production.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: deprecation mentioned (no explicit date found) · breaking-change flagged · CVE-2026-47204 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47205 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47207 — CISA KEV: not listed, EPSS 0.00