Skip to content

Tags: envoyproxy/envoy

Tags

v1.39.1

Toggle v1.39.1's commit message
repo: Release v1.39.1

**Summary of changes**:

* Security fixes:
  - [CVE-2026-73511](GHSA-m745-gh6x-349x): url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with `envoy.reloadable_features.strip_path_parameters_per_segment`.
  - [CVE-2026-73512](GHSA-r6j2-mrm5-72mg): http3: UAF on a specifically timed sequence of HTTP/3 frames.
  - [CVE-2026-73513](GHSA-jjmm-fw8p-crpw): http2: abnormal process termination on trailers received without the END_STREAM flag.
  - [CVE-2026-73546](GHSA-pv9h-4fxf-7vrg): admin: sanitize stat names before converting them to HTML. Guarded by `envoy.reloadable_features.sanitize_html_stats_names`.
  - [CVE-2026-73547](GHSA-87ph-jqwm-pg6r): ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
  - [CVE-2026-73548](GHSA-3vhp-c83q-jqc2): http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with `envoy.reloadable_features.http_pause_generic_upgrade_request_body`.
  - [CVE-2026-73549](GHSA-jp5f-qr64-c9vw): quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
  - [CVE-2026-73550](GHSA-qgf6-qvhw-4hvh): http2: dropped `Host` headers now count towards request header map size and count limits. Revert with `envoy.reloadable_features.http2_track_size_of_dropped_host_header`.
  - [CVE-2026-73551](GHSA-2w8w-rfw7-8gg4): url normalization: strip path parameters from dot and dotdot segments (`/.;`, `/..;`) so canonicalization interprets them correctly. Applies only when `normalize_path` is enabled; revert with `envoy.reloadable_features.strip_dotdot_segments_with_parameters`.
  - [CVE-2026-73552](GHSA-23xh-2qxr-3xv8): safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with `envoy.reloadable_features.re2_use_latin1_mode`.
  - [CVE-2026-73553](GHSA-77x5-xqjg-hprq): rbac: RBAC path matching now respects the route's `ignore_path_parameters_in_path_matching`, preventing authz bypass via appended path parameters. Revert with `envoy.reloadable_features.rbac_respect_ignore_path_parameters`.
  - [CVE-2026-50572](GHSA-q8wp-gf7q-m8cv): ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
  - [CVE-2026-48521](GHSA-5vff-j9p4-38j3): http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.

* Bug fixes:
  - http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via `addDecodedData()`/`addEncodedData()` immediately before returning `Continue` was silently dropped, corrupting large streamed bodies. Revert with `envoy.reloadable_features.filter_manager_forward_added_data_on_continue`.
  - ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
  - tls: fixed a memory leak in the OpenSSL compatibility layer where `SSL_get0_peer_certificates()` leaked an `X509` refcount per call, preventing certificates from being freed on connection close.
  - tls: fixed a bug where OpenSSL used glibc's allocator instead of tcmalloc, operating on a separate heap and making OpenSSL allocations invisible to tcmalloc heap profiling.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.39.1
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.39.1/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.39.1/version_history/v1.39/v1.39.1
**Full changelog**:
    v1.39.0...v1.39.1

v1.38.4

Toggle v1.38.4's commit message
repo: Release v1.38.4

**Summary of changes**:

* Security fixes:
  - [CVE-2026-73511](GHSA-m745-gh6x-349x): url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with `envoy.reloadable_features.strip_path_parameters_per_segment`.
  - [CVE-2026-73512](GHSA-r6j2-mrm5-72mg): http3: UAF on a specifically timed sequence of HTTP/3 frames.
  - [CVE-2026-73513](GHSA-jjmm-fw8p-crpw): http2: abnormal process termination on trailers received without the END_STREAM flag.
  - [CVE-2026-73546](GHSA-pv9h-4fxf-7vrg): admin: sanitize stat names before converting them to HTML. Guarded by `envoy.reloadable_features.sanitize_html_stats_names`.
  - [CVE-2026-73547](GHSA-87ph-jqwm-pg6r): ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
  - [CVE-2026-73548](GHSA-3vhp-c83q-jqc2): http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with `envoy.reloadable_features.http_pause_generic_upgrade_request_body`.
  - [CVE-2026-73549](GHSA-jp5f-qr64-c9vw): quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
  - [CVE-2026-73550](GHSA-qgf6-qvhw-4hvh): http2: dropped `Host` headers now count towards request header map size and count limits. Revert with `envoy.reloadable_features.http2_track_size_of_dropped_host_header`.
  - [CVE-2026-73551](GHSA-2w8w-rfw7-8gg4): url normalization: strip path parameters from dot and dotdot segments (`/.;`, `/..;`) so canonicalization interprets them correctly. Applies only when `normalize_path` is enabled; revert with `envoy.reloadable_features.strip_dotdot_segments_with_parameters`.
  - [CVE-2026-73552](GHSA-23xh-2qxr-3xv8): safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with `envoy.reloadable_features.re2_use_latin1_mode`.
  - [CVE-2026-73553](GHSA-77x5-xqjg-hprq): rbac: RBAC path matching now respects the route's `ignore_path_parameters_in_path_matching`, preventing authz bypass via appended path parameters. Revert with `envoy.reloadable_features.rbac_respect_ignore_path_parameters`.
  - [CVE-2026-50572](GHSA-q8wp-gf7q-m8cv): ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
  - [CVE-2026-48521](GHSA-5vff-j9p4-38j3): http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.

* Bug fixes:
  - http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via `addDecodedData()`/`addEncodedData()` immediately before returning `Continue` was silently dropped, corrupting large streamed bodies. Revert with `envoy.reloadable_features.filter_manager_forward_added_data_on_continue`.
  - ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
  - router: fixed a lifetime bug in dynamic forward proxy async host selection when the cluster is removed while lookup is still pending.
  - tls: fixed a memory leak in the OpenSSL compatibility layer where `SSL_get0_peer_certificates()` leaked an `X509` refcount per call, preventing certificates from being freed on connection close.
  - tls: fixed a bug where OpenSSL used glibc's allocator instead of tcmalloc, operating on a separate heap and making OpenSSL allocations invisible to tcmalloc heap profiling.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.4
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.38.4/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.38.4/version_history/v1.38/v1.38.4
**Full changelog**:
    v1.38.3...v1.38.4

Signed-off-by: Ryan Northey <ryan@synca.io>

v1.37.6

Toggle v1.37.6's commit message
repo: Release v1.37.6

**Summary of changes**:

* Security fixes:
  - [CVE-2026-73511](GHSA-m745-gh6x-349x): url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with `envoy.reloadable_features.strip_path_parameters_per_segment`.
  - [CVE-2026-73512](GHSA-r6j2-mrm5-72mg): http3: UAF on a specifically timed sequence of HTTP/3 frames.
  - [CVE-2026-73513](GHSA-jjmm-fw8p-crpw): http2: abnormal process termination on trailers received without the END_STREAM flag.
  - [CVE-2026-73546](GHSA-pv9h-4fxf-7vrg): admin: sanitize stat names before converting them to HTML. Guarded by `envoy.reloadable_features.sanitize_html_stats_names`.
  - [CVE-2026-73547](GHSA-87ph-jqwm-pg6r): ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
  - [CVE-2026-73548](GHSA-3vhp-c83q-jqc2): http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with `envoy.reloadable_features.http_pause_generic_upgrade_request_body`.
  - [CVE-2026-73549](GHSA-jp5f-qr64-c9vw): quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
  - [CVE-2026-73550](GHSA-qgf6-qvhw-4hvh): http2: dropped `Host` headers now count towards request header map size and count limits. Revert with `envoy.reloadable_features.http2_track_size_of_dropped_host_header`.
  - [CVE-2026-73551](GHSA-2w8w-rfw7-8gg4): url normalization: strip path parameters from dot and dotdot segments (`/.;`, `/..;`) so canonicalization interprets them correctly. Applies only when `normalize_path` is enabled; revert with `envoy.reloadable_features.strip_dotdot_segments_with_parameters`.
  - [CVE-2026-73552](GHSA-23xh-2qxr-3xv8): safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with `envoy.reloadable_features.re2_use_latin1_mode`.
  - [CVE-2026-73553](GHSA-77x5-xqjg-hprq): rbac: RBAC path matching now respects the route's `ignore_path_parameters_in_path_matching`, preventing authz bypass via appended path parameters. Revert with `envoy.reloadable_features.rbac_respect_ignore_path_parameters`.
  - [CVE-2026-50572](GHSA-q8wp-gf7q-m8cv): ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
  - [CVE-2026-48521](GHSA-5vff-j9p4-38j3): http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.

* Bug fixes:
  - http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via `addDecodedData()`/`addEncodedData()` immediately before returning `Continue` was silently dropped, corrupting large streamed bodies. Revert with `envoy.reloadable_features.filter_manager_forward_added_data_on_continue`.
  - ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
  - ext_proc: fixed a bug where unnecessary empty data chunks were processed by the filter chain. Revert with `envoy.reloadable_features.ext_proc_return_stop_iteration`.
  - router: fixed a lifetime bug in dynamic forward proxy async host selection when the cluster is removed while lookup is still pending.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.6
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.37.6/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.37.6/version_history/v1.37/v1.37.6
**Full changelog**:
    v1.37.5...v1.37.6

v1.36.10

Toggle v1.36.10's commit message
repo: Release v1.36.10

**Summary of changes**:

* Security fixes:
  - [CVE-2026-73511](GHSA-m745-gh6x-349x): url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with `envoy.reloadable_features.strip_path_parameters_per_segment`.
  - [CVE-2026-73512](GHSA-r6j2-mrm5-72mg): http3: UAF on a specifically timed sequence of HTTP/3 frames.
  - [CVE-2026-73513](GHSA-jjmm-fw8p-crpw): http2: abnormal process termination on trailers received without the END_STREAM flag.
  - [CVE-2026-73546](GHSA-pv9h-4fxf-7vrg): admin: sanitize stat names before converting them to HTML. Guarded by `envoy.reloadable_features.sanitize_html_stats_names`.
  - [CVE-2026-73547](GHSA-87ph-jqwm-pg6r): ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
  - [CVE-2026-73548](GHSA-3vhp-c83q-jqc2): http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with `envoy.reloadable_features.http_pause_generic_upgrade_request_body`.
  - [CVE-2026-73549](GHSA-jp5f-qr64-c9vw): quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
  - [CVE-2026-73550](GHSA-qgf6-qvhw-4hvh): http2: dropped `Host` headers now count towards request header map size and count limits. Revert with `envoy.reloadable_features.http2_track_size_of_dropped_host_header`.
  - [CVE-2026-73551](GHSA-2w8w-rfw7-8gg4): url normalization: strip path parameters from dot and dotdot segments (`/.;`, `/..;`) so canonicalization interprets them correctly. Applies only when `normalize_path` is enabled; revert with `envoy.reloadable_features.strip_dotdot_segments_with_parameters`.
  - [CVE-2026-73552](GHSA-23xh-2qxr-3xv8): safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with `envoy.reloadable_features.re2_use_latin1_mode`.
  - [CVE-2026-73553](GHSA-77x5-xqjg-hprq): rbac: RBAC path matching now respects the route's `ignore_path_parameters_in_path_matching`, preventing authz bypass via appended path parameters. Revert with `envoy.reloadable_features.rbac_respect_ignore_path_parameters`.
  - [CVE-2026-50572](GHSA-q8wp-gf7q-m8cv): ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
  - [CVE-2026-48521](GHSA-5vff-j9p4-38j3): http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.

* Bug fixes:
  - http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via `addDecodedData()`/`addEncodedData()` immediately before returning `Continue` was silently dropped, corrupting large streamed bodies. Revert with `envoy.reloadable_features.filter_manager_forward_added_data_on_continue`.
  - ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
  - ext_proc: fixed a bug to support two ext_proc filters configured in the chain. Revert with `envoy.reloadable_features.ext_proc_inject_data_with_state_update`.
  - router: fixed a lifetime bug in dynamic forward proxy async host selection when the cluster is removed while lookup is still pending.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.10
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.36.10/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.36.10/version_history/v1.36/v1.36.10
**Full changelog**:
    v1.36.9...v1.36.10

v1.39.0

Toggle v1.39.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
[release/main] repo: Release v1.39.0 (#46121)

v1.38.3

Toggle v1.38.3's commit message
repo: Release v1.38.3

**Summary of changes**:

* Security fixes:
  - [CVE-2026-47205](GHSA-mvh9-767w-x47j): Authz per route crash
  - [CVE-2026-47207](GHSA-68cv-hq5f-g6xv): ext_proc response in one gRPC message
  - [CVE-2026-47221](GHSA-rcff-gw58-pjpr): router internal redirects crash
  - [CVE-2026-47220](GHSA-j9wh-4qfm-wf2v): REQUESTED_SERVER_NAME crash
  - [CVE-2026-47775](GHSA-396h-jpq4-vc7p): OAuth2 code verifier padding oracle
  - [CVE-2026-48044](GHSA-m3p9-47wh-88wg): zstd RLE zip bomb
  - [CVE-2026-47204](GHSA-3jxh-8p6x-7pf6): grpc_stats filter segfault on Connect protocol requests to direct_response routes
  - [CVE-2026-47692](GHSA-wh36-hm39-mm3r): PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
  - [CVE-2026-47778](GHSA-f8x4-rw5x-f3r7): Embedded NUL in TLS SAN Truncation, Auth Bypass
  - [CVE-2026-48042](GHSA-f24p-rxw2-g6pv): Stack overflow in destructor of highly nested JSON
  - [CVE-2026-48090](GHSA-3cj2-c63f-q26f): OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
  - [CVE-2026-48497](GHSA-j6g2-wf95-q66q): Abnormal process termination in DNS UDP filter
  - [CVE-2026-48743](GHSA-8phg-2h2q-jgxf): HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
  - [CVE-2026-48706](GHSA-7q3f-gwg7-j8g4): Envoy Heap Buffer Overflow in TcpStatsdSink
  - [GHSA-p7c7-7c47-pwch](GHSA-p7c7-7c47-pwch):  Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding

* Upstream security fixes:
  - CVE-2026-47261: wasm: bumped ``com_github_wasmtime`` to resolve CVE-2026-47261.

* Behavior changes:
  - build: disabled the contrib extension ``envoy.network.connection_balance.dlb`` (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.

* Minor behavior changes:
  - tls: runtime guard ``envoy.reloadable_features.tls_certificate_compression_brotli`` is now disabled by default. When disabled, QUIC retains zlib-only certificate compression and TCP TLS performs no certificate compression. It can be re-enabled by setting the runtime guard to ``true``.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.3
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.38.3/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.38.3/version_history/v1.38/v1.38.3
**Full changelog**:
    v1.38.2...v1.38.3

v1.37.5

Toggle v1.37.5's commit message
repo: Release v1.37.5

**Summary of changes**:

* Security fixes:
  - [CVE-2026-47205](https://github.com/envoyproxy/envoy/security/advisories/GHSA-mvh9-767w-x47j):Authz per route crash
  - [CVE-2026-47207](GHSA-68cv-hq5f-g6xv): ext_proc response in one gRPC message
  - [CVE-2026-47221](GHSA-rcff-gw58-pjpr): router internal redirects crash
  - [CVE-2026-47220](GHSA-j9wh-4qfm-wf2v): REQUESTED_SERVER_NAME crash
  - [CVE-2026-47775](GHSA-396h-jpq4-vc7p): OAuth2 code verifier padding oracle
  - [CVE-2026-48044](GHSA-m3p9-47wh-88wg): zstd RLE zip bomb
  - [CVE-2026-47204](GHSA-3jxh-8p6x-7pf6): grpc_stats filter segfault on Connect protocol requests to direct_response routes
  - [CVE-2026-47692](GHSA-wh36-hm39-mm3r): PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
  - [CVE-2026-47778](GHSA-f8x4-rw5x-f3r7): Embedded NUL in TLS SAN Truncation, Auth Bypass
  - [CVE-2026-48042](GHSA-f24p-rxw2-g6pv): Stack overflow in destructor of highly nested JSON
  - [CVE-2026-48090](GHSA-3cj2-c63f-q26f): OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
  - [CVE-2026-48497](GHSA-j6g2-wf95-q66q): Abnormal process termination in DNS UDP filter
  - [CVE-2026-48743](GHSA-8phg-2h2q-jgxf): HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
  - [CVE-2026-48706](GHSA-7q3f-gwg7-j8g4): Envoy Heap Buffer Overflow in TcpStatsdSink
  - [GHSA-p7c7-7c47-pwch](GHSA-p7c7-7c47-pwch):  Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding

* Upstream security fixes:
  - CVE-2026-47261: wasm: bumped ``com_github_wasmtime`` to resolve CVE-2026-47261.

* Behavior changes:
  - build: disabled the contrib extension ``envoy.network.connection_balance.dlb`` (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.5
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.37.5/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.37.5/version_history/v1.37/v1.37.5
**Full changelog**:
    v1.37.4...v1.37.5

v1.36.9

Toggle v1.36.9's commit message
repo: Release v1.36.9

**Summary of changes**:

* Upstream security fixes:
  - [CVE-2026-47205](https://github.com/envoyproxy/envoy/security/advisories/GHSA-mvh9-767w-x47j):Authz per route crash
  - [CVE-2026-47207](GHSA-68cv-hq5f-g6xv): ext_proc response in one gRPC message
  - [CVE-2026-47221](GHSA-rcff-gw58-pjpr): router internal redirects crash
  - [CVE-2026-47775](GHSA-396h-jpq4-vc7p): OAuth2 code verifier padding oracle
  - [CVE-2026-48044](GHSA-m3p9-47wh-88wg): zstd RLE zip bomb
  - [CVE-2026-47204](GHSA-3jxh-8p6x-7pf6): grpc_stats filter segfault on Connect protocol requests to direct_response routes
  - [CVE-2026-47692](GHSA-wh36-hm39-mm3r): PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
  - [CVE-2026-47778](GHSA-f8x4-rw5x-f3r7): Embedded NUL in TLS SAN Truncation, Auth Bypass
  - [CVE-2026-48042](GHSA-f24p-rxw2-g6pv): Stack overflow in destructor of highly nested JSON
  - [CVE-2026-48090](GHSA-3cj2-c63f-q26f): OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
  - [CVE-2026-48497](GHSA-j6g2-wf95-q66q): Abnormal process termination in DNS UDP filter
  - [CVE-2026-48743](GHSA-8phg-2h2q-jgxf): HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
  - [CVE-2026-48706](GHSA-7q3f-gwg7-j8g4): Envoy Heap Buffer Overflow in TcpStatsdSink
  - [GHSA-p7c7-7c47-pwch](GHSA-p7c7-7c47-pwch): Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding

* Upstream security fixes:
  - CVE-2026-47261: wasm: bumped `com_github_wasmtime` to resolve CVE-2026-47261.

* Behavior changes:
  - build: disabled the contrib extension `envoy.network.connection_balance.dlb` (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.9
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.36.9/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.36.9/version_history/v1.36/v1.36.9
**Full changelog**:
    v1.36.8...v1.36.9

v1.35.13

Toggle v1.35.13's commit message
repo: Release v1.35.13

**Summary of changes**:

* Security fixes:
  - [CVE-2026-47207](GHSA-68cv-hq5f-g6xv): ext_proc response in one gRPC message
  - [CVE-2026-47221](GHSA-rcff-gw58-pjpr): router internal redirects crash
  - [CVE-2026-47775](GHSA-396h-jpq4-vc7p): OAuth2 code verifier padding oracle
  - [CVE-2026-48044](GHSA-m3p9-47wh-88wg): zstd RLE zip bomb
  - [CVE-2026-47204](GHSA-3jxh-8p6x-7pf6): grpc_stats filter segfault on Connect protocol requests to direct_response routes
  - [CVE-2026-47692](GHSA-wh36-hm39-mm3r): PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled
spillover into the upstream application stream
  - [CVE-2026-47778](GHSA-f8x4-rw5x-f3r7): Embedded NUL in TLS SAN Truncation, Auth Bypass
  - [CVE-2026-48042](GHSA-f24p-rxw2-g6pv): Stack overflow in destructor of highly nested JSON
  - [CVE-2026-48090](GHSA-3cj2-c63f-q26f): OAuth2 filter late async token completion after stream teardown results in UAF/crash risk
  - [CVE-2026-48497](GHSA-j6g2-wf95-q66q): DNS filter abnormal process termination on long query name
  - [CVE-2026-48743](GHSA-8phg-2h2q-jgxf): HTTP/3 headers-only request/response content-length not validated
  - [CVE-2026-48706](GHSA-7q3f-gwg7-j8g4): TcpStatsdSync buffer overflow with large stats name
  - [GHSA-p7c7-7c47-pwch](GHSA-p7c7-7c47-pwch): Denial-of-Service Attack Against the HTTP/3 Stack via QPACK Blocked Decoding

* Upstream security fixes:
  - CVE-2026-47261: wasm: bumped `com_github_wasmtime` to resolve CVE-2026-47261.

* Behavior changes:
  - build: disabled the contrib extension `envoy.network.connection_balance.dlb` (Intel DLB connection balancer) at the Bazel layer for all builds and platforms due to a breakage at the source archive. See #45491 for local workarounds.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.13
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.35.13/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.35.13/version_history/v1.35/v1.35.13
**Full changelog**:
    v1.35.12...v1.35.13

Signed-off-by: Ryan Northey <ryan@synca.io>

v1.38.2

Toggle v1.38.2's commit message
repo: Release v1.38.2

**Summary of changes**:

* Bug fixes:
  - runtime: fixed RTDS runtime guard override removal so deleting an override restores the process-wide runtime guard value to the default value.

* New features:
  - http2: added opt-in histograms for HTTP/2 header statistics, including header-entry count, header-map byte size, reassembled ``cookie`` header length, and individual ``cookie`` header count. Enable with ``envoy.reloadable_features.http2_record_histograms``; the histograms and runtime guard will be removed in a future Envoy release.
  - http2: added ``envoy.reloadable_features.http2_max_cookies_size_in_kb`` to limit the size of the reassembled ``cookie`` header. By default, no cookie-size limit is enforced.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.38.2
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.38.2/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.38.2/version_history/v1.38/v1.38.2
**Full changelog**:
    v1.38.1...v1.38.2