repo: Release v1.39.2
Summary of changes:
-
Security fixes:
- CVE-2026-35189: tls: updated BoringSSL to fix excessive memory allocation when parsing certificates with
nameRelativeToCRLIssuerCRL Distribution Points, which could be exploited for remote denial of service during TLS handshakes.
- CVE-2026-35189: tls: updated BoringSSL to fix excessive memory allocation when parsing certificates with
-
Build/packaging:
- Removed Debian bullseye (11) packaging, as bullseye is end-of-life and its repositories are no longer available on the main Debian mirrors.
- Moved Debian
.changesand release checksum signing into the Bazel release assembly, with an audit of signing actions. - Refreshed the Ubuntu build and distroless Docker base images.
Docker images:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.2
Docs:
https://www.envoyproxy.io/docs/envoy/v1.39.2/
Release notes:
https://www.envoyproxy.io/docs/envoy/v1.39.2/version_history/v1.39/v1.39.2
Full changelog:
v1.39.1...v1.39.2