- Patched multiple security CVEs (multivalue header RBAC bypass, IPv6 address crash, JSON OOB write, downstream reset handling)
- Fixed OAuth2 token refresh host rewriting bug
- Updated dependencies: GoogleURL source, Kafka test binary, Docker base images
Official Envoy changelog summary with source attribution, release tags, and community reactions.
Track this Envoy release note alongside related changelog updates, risky changes, and weekly digest signals from the developer community.
Every summary should remain traceable to the original changelog or release source.
Turn this Envoy release note into a weekly digest for the tools you actually use.
Create digest