github envoyproxy/envoy v1.38.5

one hour ago

repo: Release v1.38.5

Summary of changes:

  • Security fixes:

    • CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. The BoringSSL FIPS build (--config=boringssl-fips) does not receive this patch.
  • Build/packaging:

    • Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
    • Moved Debian .changes and release checksum signing into the Bazel release assembly, with an audit of signing actions.
    • Refreshed the Ubuntu build image.

Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.5
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.5/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.5/version_history/v1.38/v1.38.5
Full changelog:
v1.38.4...v1.38.5

Don't miss a new envoy release

NewReleases is sending notifications on new releases.