v1.37.3
envoyproxy/envoyv1.37.3Jun 4, 2026by publish-envoy[bot]
AI Summary
This release addresses critical security vulnerabilities, including fixes for an HPACK cookie-bomb, HMAC timing side-channel leaks, and a crash in AES-CBC token decryption. It also includes a bug fix for a shutdown race condition in the load report ADS stream.
Key Highlights
- Security patch for HPACK cookie-bomb vulnerability (CVE-2026-47774) protecting against memory exhaustion.
- Fixed HMAC timing side-channel vulnerability in OAuth2 verification.
- Fixed AES-CBC decryption crash that could spuriously succeed on secret mismatch.
- Applied nghttp2 CVE-2026-27135 patch.
- Fixed shutdown race condition in load reports with ADS stream.
Full Release Notes
**Summary of changes**:
* Security fixes:
- [CVE-2026-47774](https://github.com/envoyproxy/envoy/security/advisories/GHSA-22m2-hvr2-xqc8): http2: HTTP/2 streams are now reset if they violate the configured maximum header list size. Uncompressed cookies now count towards ``mutable_max_request_headers_kb`` and ``max_headers_count`` limits, protecting against an HPACK cookie-bomb that could cause excessive memory usage. This can be reverted with ``envoy.reloadable_features.http2_include_cookies_in_limits``.
- oauth2: fixed a timing side-channel in HMAC verification that could leak HMAC secret validity.
- oauth2: fixed a crash where AES-CBC decryption of token cookies could spuriously succeed (~1/256) on a secret mismatch, tripping a ``HeaderString`` validation assert.
- CVE-2026-27135: http2: applied nghttp2 CVE-2026-27135 patch.
* Bug fixes:
- load_report: fixed a shutdown race with ADS stream by introducing proper gRPC stream cleanup.
**Docker images**:
https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.37.3
**Docs**:
https://www.envoyproxy.io/docs/envoy/v1.37.3/
**Release notes**:
https://www.envoyproxy.io/docs/envoy/v1.37.3/version_history/v1.37/v1.37.3
**Full changelog**:
https://github.com/envoyproxy/envoy/compare/v1.37.2...v1.37.3
Signed-off-by: Jonh Wendell <jonh.wendell@redhat.com>
Signed-off-by: Greg Greenway <ggreenway@apple.com>
Signed-off-by: Ryan Northey <ryan@synca.io>