github envoyproxy/envoy v1.35.7

latest release: v1.36.3
4 hours ago

Summary of changes:

  • Security fixes:
    • CVE-2025-64527: Envoy crashes when JWT authentication is configured with the remote JWKS fetching
    • CVE-2025-66220: TLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null byte
    • CVE-2025-64763: Potential request smuggling from early data after the CONNECT upgrade

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.7
Docs:
https://www.envoyproxy.io/docs/envoy/v1.35.7/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.35.7/version_history/v1.35/v1.35.7
Full changelog:
v1.35.6...v1.35.7

Signed-off-by: Ryan Northey ryan@synca.io
Signed-off-by: Boteng Yao boteng@google.com

Don't miss a new envoy release

NewReleases is sending notifications on new releases.