repo: Release v1.38.5
Summary of changes:
-
Security fixes:
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
nameRelativeToCRLIssuerCRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes. The BoringSSL FIPS build (--config=boringssl-fips) does not receive this patch.
- CVE-2026-35189: tls: patched BoringSSL to fix excessive memory allocation when parsing certificates with
-
Build/packaging:
- Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
- Moved Debian
.changesand release checksum signing into the Bazel release assembly, with an audit of signing actions. - Refreshed the Ubuntu build image.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.5
Docs:
https://www.envoyproxy.io/docs/envoy/v1.38.5/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.38.5/version_history/v1.38/v1.38.5
Full changelog:
v1.38.4...v1.38.5