v1.35.4

envoyproxy/envoyv1.35.4Oct 14, 2025by publish-envoy[bot]

AI Summary

This release focuses on resolving dependency CVEs across various components including FIPS/Go, LuaJIT, and Kafka.

Key Highlights

  • Resolved CVE-2025-0913 for fips/go
  • Resolved CVEs for luajit (2024-25176, 2024-25177, 2024-25178)
  • Resolved CVEs for kafka (2025-27817, 2025-27818)

Full Release Notes

**Summary of changes**:

* Security updates:

  Resolve dependency CVEs:
  - CVE-2025-0913: fips/go
  - CVE-2024-25176: luajit
  - CVE-2024-25177: luajit
  - CVE-2024-25178: luajit
  - CVE-2025-27817: kafka
  - CVE-2025-27818: kafka

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.35.4
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.35.4/
**Release notes**:

https://www.envoyproxy.io/docs/envoy/v1.35.4/version_history/v1.35/v1.35.4
**Full changelog**:
    https://github.com/envoyproxy/envoy/compare/v1.35.3...v1.35.4

Signed-off-by: Ryan Northey <ryan@synca.io>
Signed-off-by: Rohit Agrawal <rohit.agrawal@databricks.com>