v1.36.10

envoyproxy/envoyv1.36.10Aug 26, 2026by publish-envoy[bot]

AI Summary

This release addresses a wide range of security vulnerabilities including URL normalization, HTTP/3 and HTTP/2 use-after-free issues, and admin sanitization, alongside bug fixes in the filter manager, ext_proc, and router components.

Key Highlights

  • Fixes multiple CVEs including URL normalization, HTTP/3 UAF, HTTP/2 termination, Admin sanitization, ext_authz, QUIC, safe_regex, and RBAC bypass issues.
  • Resolves a filter manager bug that could corrupt large streamed bodies by silently dropping data frames.
  • Fixes lifetime bugs in the ext_proc filter and the underlying gRPC async client.
  • Corrects dynamic forward proxy async host selection when clusters are removed during a lookup.

Full Release Notes

**Summary of changes**:

* Security fixes:
  - [CVE-2026-73511](https://github.com/envoyproxy/envoy/security/advisories/GHSA-m745-gh6x-349x): url normalization: strip path parameters from individual path segments per RFC 3986 section 3.3. Revert with `envoy.reloadable_features.strip_path_parameters_per_segment`.
  - [CVE-2026-73512](https://github.com/envoyproxy/envoy/security/advisories/GHSA-r6j2-mrm5-72mg): http3: UAF on a specifically timed sequence of HTTP/3 frames.
  - [CVE-2026-73513](https://github.com/envoyproxy/envoy/security/advisories/GHSA-jjmm-fw8p-crpw): http2: abnormal process termination on trailers received without the END_STREAM flag.
  - [CVE-2026-73546](https://github.com/envoyproxy/envoy/security/advisories/GHSA-pv9h-4fxf-7vrg): admin: sanitize stat names before converting them to HTML. Guarded by `envoy.reloadable_features.sanitize_html_stats_names`.
  - [CVE-2026-73547](https://github.com/envoyproxy/envoy/security/advisories/GHSA-87ph-jqwm-pg6r): ext_authz: abnormal process termination on requests without a URI path (i.e. CONNECT).
  - [CVE-2026-73548](https://github.com/envoyproxy/envoy/security/advisories/GHSA-3vhp-c83q-jqc2): http: payload sent before a generic HTTP upgrade was accepted could be interpreted as a pipelined HTTP/1 request and poison a shared upstream connection. Revert with `envoy.reloadable_features.http_pause_generic_upgrade_request_body`.
  - [CVE-2026-73549](https://github.com/envoyproxy/envoy/security/advisories/GHSA-jp5f-qr64-c9vw): quic: crash handling scoped IPv6 addresses in QUIC client connections and Original Dst clusters.
  - [CVE-2026-73550](https://github.com/envoyproxy/envoy/security/advisories/GHSA-qgf6-qvhw-4hvh): http2: dropped `Host` headers now count towards request header map size and count limits. Revert with `envoy.reloadable_features.http2_track_size_of_dropped_host_header`.
  - [CVE-2026-73551](https://github.com/envoyproxy/envoy/security/advisories/GHSA-2w8w-rfw7-8gg4): url normalization: strip path parameters from dot and dotdot segments (`/.;`, `/..;`) so canonicalization interprets them correctly. Applies only when `normalize_path` is enabled; revert with `envoy.reloadable_features.strip_dotdot_segments_with_parameters`.
  - [CVE-2026-73552](https://github.com/envoyproxy/envoy/security/advisories/GHSA-23xh-2qxr-3xv8): safe_regex: switch charset mode from UTF-8 to Latin1, as HTTP headers are not UTF-8 encoded. Revert with `envoy.reloadable_features.re2_use_latin1_mode`.
  - [CVE-2026-73553](https://github.com/envoyproxy/envoy/security/advisories/GHSA-77x5-xqjg-hprq): rbac: RBAC path matching now respects the route's `ignore_path_parameters_in_path_matching`, preventing authz bypass via appended path parameters. Revert with `envoy.reloadable_features.rbac_respect_ignore_path_parameters`.
  - [CVE-2026-50572](https://github.com/envoyproxy/envoy/security/advisories/GHSA-q8wp-gf7q-m8cv): ext_authz: UAF when ext_authz over HTTP causes a request to be rejected.
  - [CVE-2026-48521](https://github.com/envoyproxy/envoy/security/advisories/GHSA-5vff-j9p4-38j3): http3: abnormal process termination when upstream protocol is selected via ALPN and the server uses HTTP/3.

* Bug fixes:
  - http: fixed a filter manager bug where a body frame moved into the filter-manager buffer via `addDecodedData()`/`addEncodedData()` immediately before returning `Continue` was silently dropped, corrupting large streamed bodies. Revert with `envoy.reloadable_features.filter_manager_forward_added_data_on_continue`.
  - ext_proc: fixed multiple lifetime bugs in the ext_proc filter and the underlying gRPC async client that could lead to use-after-free or double delivery of callbacks.
  - ext_proc: fixed a bug to support two ext_proc filters configured in the chain. Revert with `envoy.reloadable_features.ext_proc_inject_data_with_state_update`.
  - router: fixed a lifetime bug in dynamic forward proxy async host selection when the cluster is removed while lookup is still pending.

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.36.10
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.36.10/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.36.10/version_history/v1.36/v1.36.10
**Full changelog**:
    https://github.com/envoyproxy/envoy/compare/v1.36.9...v1.36.10

Signed-off-by: Yan Avlasov <yavlasov@google.com>
Signed-off-by: Kateryna Nezdolii <kateryna.nezdolii@gmail.com>
Signed-off-by: Jonh Wendell <jonh.wendell@redhat.com>
Signed-off-by: Ryan Northey <ryan@synca.io>