Summary of changes:
-
Security fixes:
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
nameRelativeToCRLIssuerCRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. Note that the FIPS build is not patched.
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
-
Build/packaging:
- Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.11
Docs:
https://www.envoyproxy.io/docs/envoy/v1.36.11/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.36.11/version_history/v1.36/v1.36.11
Full changelog:
v1.36.10...v1.36.11
Signed-off-by: Greg Greenway ggreenway@apple.com
Signed-off-by: Kateryna Nezdolii kateryna.nezdolii@gmail.com
Signed-off-by: Ryan Northey ryan@synca.io