v1.34.8

envoyproxy/envoyv1.34.8Oct 14, 2025by publish-envoy[bot]

AI Summary

This release focuses on resolving dependency CVEs across Curl, gRPC, LuaJIT, and Kafka.

Key Highlights

  • Resolved CVE-2025-0725 for curl
  • Resolved CVEs for gRPC (2024-11407)
  • Resolved CVEs for luajit (2024-25176, 2024-25177, 2024-25178)
  • Resolved CVEs for kafka (2025-27817, 2025-27818)

Full Release Notes

**Summary of changes**:

* Security updates:

  Resolve dependency CVEs:
  - CVE-2025-0725: curl
  - CVE-2024-11407: gRPC
  - CVE-2024-25176: luajit
  - CVE-2024-25177: luajit
  - CVE-2024-25178: luajit
  - CVE-2025-27817: kafka
  - CVE-2025-27818: kafka

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.34.8
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.34.8/
**Release notes**:

https://www.envoyproxy.io/docs/envoy/v1.34.8/version_history/v1.34/v1.34.8
**Full changelog**:
    https://github.com/envoyproxy/envoy/compare/v1.34.7...v1.34.8

Signed-off-by: Ryan Northey <ryan@synca.io>
Signed-off-by: Rohit Agrawal <rohit.agrawal@databricks.com>