This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Network Security
✓ No known CVEs patched
This release patches 1 known CVE
Topics
aigateway
beyondcorp
gateway
go
iam
identity
+5 more
identity-aware-proxy
pomerium
proxy
vpn
zero-trust
Affected surfaces
deps
Summary
AI summaryUpdates Dependency Updates, https://github.com/envoyproxy/envoy/security/advisories/GHSA-22m2-hvr2-xqc8, and envoyconfig across a mixed release.
Full changelog
Security
This release includes an update to Envoy v1.36.8, to address CVE-2026-47774.
What's Changed
Changed
- envoyconfig: increase header size limits by @kenjenkins in https://github.com/pomerium/pomerium/pull/6452
Dependency Updates
- envoy: update envoy-custom to v1.36.8-p1 by @kenjenkins in https://github.com/pomerium/pomerium/pull/6450
- dependency updates for security patches by @kenjenkins in https://github.com/pomerium/pomerium/pull/6454
Full Changelog: https://github.com/pomerium/pomerium/compare/v0.32.8...v0.32.9
Security Fixes
- CVE-2026-47774 — fixed by updating Envoy to v1.36.8‑p1 (GHSA-22m2-hvr2-xqc8)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]