v1.8.5
4 minute read
Date: September 28, 2026
Envoy v1.38.5 fixes CVE-2026-35189, a BoringSSL excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points that could be exploited for remote denial of service during TLS handshakes.
Override the Envoy Proxy image to docker.io/envoyproxy/envoy:distroless-v1.38.5 as described in Upgrading Envoy Proxy to v1.38.5. The BoringSSL FIPS build of Envoy does not receive this patch.
Upgrading Envoy Proxy to v1.38.5
Changing the image rolls out the Envoy Proxy pods. Pick the option that matches how you configure the Envoy Proxy image.
Helm. Set the default Envoy Proxy image for the release:
helm upgrade eg oci://docker.io/envoyproxy/gateway-helm --version v1.8.5 -n envoy-gateway-system --reuse-values \
--set global.images.envoyProxy.image=docker.io/envoyproxy/envoy:distroless-v1.38.5
See the Helm chart values for details on global.images.envoyProxy.image.
EnvoyGateway configuration without Helm. Set the image under envoyProxy in the envoy-gateway-config ConfigMap (use envoyDaemonSet instead of envoyDeployment if you run Envoy as a DaemonSet):
envoyProxy:
provider:
type: Kubernetes
kubernetes:
envoyDeployment:
container:
image: docker.io/envoyproxy/envoy:distroless-v1.38.5
EnvoyProxy resource. The two options above set a default image only. An EnvoyProxy attached through a GatewayClass or Gateway parametersRef replaces that default unless its mergeType is StrategicMerge or JSONMerge. If you attach an EnvoyProxy with no mergeType, or one that already pins an Envoy image, set the image on that EnvoyProxy:
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyProxy
metadata:
name: custom-proxy-config
namespace: default
spec:
provider:
type: Kubernetes
kubernetes:
envoyDeployment:
container:
image: docker.io/envoyproxy/envoy:distroless-v1.38.5
See Customize EnvoyProxy Image for details.
To check the image each Envoy Proxy Deployment is running:
kubectl get deployments -A -l app.kubernetes.io/managed-by=envoy-gateway,app.kubernetes.io/component=proxy \
-o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}{"\t"}{.spec.template.spec.containers[?(@.name=="envoy")].image}{"\n"}{end}'
Breaking changes
Security updates
- Prevent user-defined proxies from conflicting with or using controller-owned resources in ControllerNamespace mode. The following are now rejected: resource names colliding with
envoy-gatewayorenvoy-gateway-config; service account names matching the controller’s own SA or the certgen SA (<fullname>-certgen, where<fullname>is the Helm release fullname, defaulting toenvoy-gateway); volumes mounting theenvoy-gatewaySecret or ConfigMap; and environment variables referencing those resources viasecretKeyRef,configMapKeyRef, orenvFrom. - Added an
EnvoyProxyPatchruntime flag toEnvoyGateway. EnvoyProxy Kubernetes resourcepatchfields can grant arbitrary access to resources applied by Envoy Gateway’s more privileged ServiceAccount when EnvoyProxy is namespace-scoped and tenant-authored. The flag is enabled by default to preserve pre-existing behavior; multi-tenant clusters where tenants can author their own EnvoyProxy resources should disable it throughruntimeFlags.disabled. - Fixed a panic in the xDS server’s Kubernetes JWT authentication when the TokenReview response contains an
Extrafield without the pod name key (authentication.kubernetes.io/pod-name). Such tokens (e.g. service account tokens not bound to a pod) are now rejected with anUnauthenticatederror instead of crashing the control plane.
New features
Bug fixes
- Fixed
rateLimitDeployment.pod.priorityClassNamebeing ignored when rendering the rate limit Deployment, so the configured PriorityClass is now applied to the rate limit pod the same way it is for the Envoy Proxy deployment. - Fixed the xDS translator emitting equivalent-but-byte-different resources on every reconcile: filter typed_config was marshaled non-deterministically, so proto map fields (such as an access log’s
json_format) re-ordered their keys each translation and caused repeated no-op xDS pushes. Typed configs are now marshaled deterministically. - Fixed HTTPRoute status collapsing when a route had two parentRefs to the same Gateway differing only by port (with no sectionName). IsParentRefEqual short-circuited before comparing Port, so both refs resolved to the same RouteParentStatus and one listener’s verdict overwrote the other’s — a route accepted on one listener could report Accepted: False borrowed from another. Listener selection and the data plane were unaffected; only the reported status was wrong.
- Fixed local rate limiting for Distinct client selectors to retain up to 10,000 per-value token buckets per wildcard descriptor by applying the cache limit to each route’s filter configuration instead of relying on Envoy’s default of 20.
- Fixed
ClientTrafficPolicyrejecting BoringSSL equal-preference cipher groups such as[ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]as an unsupported cipher suite. Each member of a group is now validated on its own. - Fixed HTTPS and TLS listeners from different merged Gateways sharing a port and a hostname being accepted, which produced two Envoy filter chains with the same SNI match and caused Envoy to reject the listener.
- Fixed the shutdown manager exiting after the minimum drain period while UDP proxy sessions were still active. The drain now also waits for
udp.*.downstream_sess_activeto reach the exit threshold. UDP sessions only close on their idle timeout (60s by default), so a proxy that has handled UDP traffic recently may wait until the drain timeout before exiting. - Fixed a duplicate filter chain matcher error when a TLS listener with no attached routes shares a port with an HTTPS listener, which caused Envoy to reject every subsequent xDS update to that listener.
- Fixed a panic during shutdown caused by closing the shared
infraIR/pResourceschannels and resources maps before all runner goroutines still consuming or writing to them had exited.
Performance improvements
- Reduced repeated JSON decoding and encoding when JSONPath patches match multiple locations.
Deprecations
Other changes
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.