Envoy Proxy version lifecycle
tool · CNCF
Current status
Supported version lines, end-of-life status, and latest releases for Envoy Proxy — derived from official vendor sources, not third-party EOL aggregators.
Envoy is a high-performance edge and service proxy designed for cloud-native applications.
Security: 12 tracked advisories · 1 in CISA KEV. Details below — lifecycle and vulnerability status are separate.
Official site →Version lines
40
Supported
4
EOL lines
36
Latest stable
1.39.1
2026-08-27
Releases tracked
278
At a glance
Latest release
1.39.1
Line 1.39
Recommended support line
1.39
standard support
Status
STANDARD SUPPORT
Newest supported: 1.39
EOL
2027-07-14
2 line(s) approaching EOL
Plan upgrade from Envoy Proxy 1.37 →
EOL lines include 1.35, 1.34, 1.33, 1.32, 1.31 (+31 more).
Recommended line: 1.39 (newest supported line with lowest lifecycle risk — not blindly “latest”).
Supported versions
4 currently supported release lines.
End-of-life versions
Historical and unsupported release lines. Exact EOL dates shown only when published by the vendor.
| Version line | Latest release | Lifecycle | EOL | Risk |
|---|---|---|---|---|
| 1.35 | 1.35.13 | end of lifehigh | 2026-07-23 | high |
| 1.34 | 1.34.14 | end of lifehigh | 2026-04-15 | high |
| 1.33 | 1.33.14 | end of lifehigh | 2026-01-14 | high |
| 1.32 | 1.32.13 | end of lifehigh | 2025-10-15 | high |
| 1.31 | 1.31.10 | end of lifehigh | 2025-07-19 | high |
| 1.30 | 1.30.11 | end of lifehigh | 2025-04-16 | high |
| 1.29 | 1.29.12 | end of lifehigh | 2025-01-16 | high |
| 1.28 | 1.28.7 | end of lifehigh | 2024-10-19 | high |
| 1.27 | 1.27.7 | end of lifehigh | 2024-07-26 | high |
| 1.26 | 1.26.8 | end of lifehigh | 2024-04-18 | high |
| 1.25 | 1.25.11 | end of lifehigh | 2024-01-18 | high |
| 1.24 | 1.24.12 | end of lifehigh | 2023-10-19 | high |
| 1.23 | 1.23.12 | end of lifehigh | 2023-07-15 | high |
| 1.22 | 1.22.11 | end of lifehigh | 2023-04-15 | high |
| 1.21 | 1.21.6 | end of lifehigh | 2023-01-12 | high |
| 1.20 | 1.20.7 | end of lifehigh | 2022-10-05 | high |
| 1.19 | 1.19.5 | end of lifehigh | 2022-07-14 | high |
| 1.18 | 1.18.6 | end of lifehigh | 2022-04-15 | high |
| 1.17 | 1.17.4 | end of lifehigh | 2022-01-11 | high |
| 1.16 | 1.16.5 | end of lifehigh | 2021-10-08 | high |
| 1.15 | 1.15.5 | end of lifehigh | 2021-07-07 | high |
| 1.14 | 1.14.7 | end of lifehigh | 2021-04-08 | high |
| 1.13 | 1.13.8 | end of lifehigh | 2021-01-20 | high |
| 1.12 | 1.12.7 | end of lifehigh | 2020-11-01 | high |
| 1.11 | 1.11.2 | end of lifehigh | 2020-07-11 | high |
| 1.10 | 1.10.0 | end of lifehigh | 2020-04-05 | high |
| 1.9 | 1.9.1 | end of lifehigh | 2019-12-20 | high |
| 1.8 | 1.8.0 | end of lifehigh | 2019-10-04 | high |
| 1.7 | 1.7.1 | end of lifehigh | 2019-06-21 | high |
| 1.6 | 1.6.0 | end of lifehigh | 2019-03-20 | high |
| 1.5 | 1.5.0 | end of lifehigh | 2018-12-05 | high |
| 1.4 | 1.4.0 | end of lifehigh | 2018-08-24 | high |
| 1.3 | 1.3.0 | end of lifehigh | 2018-05-17 | high |
| 1.2 | 1.2.0 | end of lifehigh | 2018-03-07 | high |
| 1.1 | 1.1.0 | end of lifehigh | 2017-11-30 | high |
| 1.0 | 1.0.0 | end of lifehigh | 2017-09-12 | high |
Lifecycle overview
Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.
- 1.39standard support · EOL 2027-07-14standard support
- 1.38standard support · EOL 2027-04-23standard support
- 1.37standard support · EOL 2027-01-13standard support
- 1.36standard support · EOL 2026-10-14standard support
- 1.35end of life · EOL 2026-07-23standard supportend of life
- 1.34end of life · EOL 2026-04-15standard supportend of life
- 1.33end of life · EOL 2026-01-14standard supportend of life
- 1.32end of life · EOL 2025-10-15standard supportend of life
- 1.31end of life · EOL 2025-07-19standard supportend of life
- 1.30end of life · EOL 2025-04-16standard supportend of life
- 1.29end of life · EOL 2025-01-16standard supportend of life
- 1.28end of life · EOL 2024-10-19standard supportend of life
- 1.27end of life · EOL 2024-07-26standard supportend of life
- 1.26end of life · EOL 2024-04-18standard supportend of life
- 1.25end of life · EOL 2024-01-18standard supportend of life
- 1.24end of life · EOL 2023-10-19standard supportend of life
Showing 16 of 40 lines with lifecycle periods. See the directory below for the full list.
Known exploited vulnerabilities
CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.
- CVE-2023-44487Known exploited
HTTP/2 Rapid Reset Attack Vulnerability
- CISA KEV:
- listed · added 2023-10-10 · due 2023-10-31
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-400
- Affected:
- >=1.5,<1.1; <3.4.2; <10.5.3; <9.4.0; >=12.0.0,<12.0.2; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <2023-10-08; <2.7.5; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; <2023.10.16.00; >=1.21.0,<1.21.3; <0.17.0; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.19.0,<1.19.1; <=2.427; <4.2.2; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; >=20.0.0,<20.8.1; <1.21.4.3; <2.5.0; >=4.0,<=4.0; >=3.0.0-beta3,<2.10.5
- Fixed in:
- 1.1, 3.4.2, 10.5.3, 9.4.0, 12.0.2, 9.2.3, 1.28.0, 2023-10-08, 2.7.5, 7.0.12, 2023.10.16.00, 1.21.3, 0.17.0, 1.58.3, 1.19.1, 4.2.2, 1.26.0, 4.1.100, 1.57.0, 20.8.1, 1.21.4.3, 2.5.0, 2.10.5
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- Known vulnerabilities
- 12
- Known exploited
- 1
- Highest CVSS
- 7.5
- CVE-2023-44487Known exploited
HTTP/2 Rapid Reset Attack Vulnerability
- CISA KEV:
- listed · added 2023-10-10 · due 2023-10-31
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-400
- Affected:
- >=1.5,<1.1; <3.4.2; <10.5.3; <9.4.0; >=12.0.0,<12.0.2; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <2023-10-08; <2.7.5; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; <2023.10.16.00; >=1.21.0,<1.21.3; <0.17.0; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.19.0,<1.19.1; <=2.427; <4.2.2; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; >=20.0.0,<20.8.1; <1.21.4.3; <2.5.0; >=4.0,<=4.0; >=3.0.0-beta3,<2.10.5
- Fixed in:
- 1.1, 3.4.2, 10.5.3, 9.4.0, 12.0.2, 9.2.3, 1.28.0, 2023-10-08, 2.7.5, 7.0.12, 2023.10.16.00, 1.21.3, 0.17.0, 1.58.3, 1.19.1, 4.2.2, 1.26.0, 4.1.100, 1.57.0, 20.8.1, 1.21.4.3, 2.5.0, 2.10.5
- CVE-2026-48090
Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-47220
Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-47205
Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-47692
Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-47207
Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-48706
Envoy Heap Buffer Overflow in TcpStatsdSink
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-47204
Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-47221
Envoy: Null pointer deref in internal redirects
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-48743
Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-48497
Envoy: Abnormal process termination in DNS UDP filter
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
- CVE-2026-48044
Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion
- Affected:
- >=1.38.0,<1.38.3
- Fixed in:
- 1.38.3
- Source:
- OSV source · Advisory
Compare versions
Side-by-side view of the most relevant release lines.
Recent releases
Latest release date 2026-08-27 · 4 in last 30 days · 14 in last 90 days
- 2026-08-27
- 2026-08-26
- 2026-08-26
- 2026-08-26
1.36.10
Line 1.36 · standard support - 2026-07-14
- 2026-06-23
- 2026-06-23
- 2026-06-23
- 2026-06-23
1.35.13
Line 1.35 · end of life - 2026-06-10
Should I upgrade?
EOL approaching
Envoy Proxy 1.36 reaches end of life on 2026-10-14. Preferred line: 1.39.
Upgrade planning
Plan upgrades from Envoy Proxy version lines that have newer supported options.
Data coverage
- Version lines
- 40
- Concrete releases
- 278
- Supported lines
- 4
- EOL lines
- 36
- Lifecycle coverage
- 40/40
- EOL coverage
- 40/40
- Provenance coverage
- 40/40
Data freshness
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Data last checked
- 2026-09-02
- Latest source update
- 2026-09-02
Sources
First-party and other registered sources contributing release and lifecycle facts.
- Envoy RELEASES.md Policyfirst party · high
Official source: https://raw.githubusercontent.com/envoyproxy/envoy/main/RELEASES.md
Last verified 2026-09-02
- Envoy GitHub Releasesfirst party
Official source: https://github.com/envoyproxy/envoy/releases
Last checked 2026-09-02
- OSV.devfirst party
Official source: https://osv.dev
Last checked 2026-09-02
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Last checked 2026-09-02
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Last checked 2026-09-02
Version line directory
Complete navigation into detailed version-line pages.
Currently supported
End of life
| Version line | Status | Latest release | Released | EOL |
|---|---|---|---|---|
| 1.35 | end of lifehigh | 1.35.13 | 2026-06-23 | 2026-07-23 |
| 1.34 | end of lifehigh | 1.34.14 | 2026-04-10 | 2026-04-15 |
| 1.33 | end of lifehigh | 1.33.14 | 2025-12-10 | 2026-01-14 |
| 1.32 | end of lifehigh | 1.32.13 | 2025-10-13 | 2025-10-15 |
| 1.31 | end of lifehigh | 1.31.10 | 2025-07-18 | 2025-07-19 |
| 1.30 | end of lifehigh | 1.30.11 | 2025-03-25 | 2025-04-16 |
| 1.29 | end of lifehigh | 1.29.12 | 2024-12-18 | 2025-01-16 |
| 1.28 | end of lifehigh | 1.28.7 | 2024-09-19 | 2024-10-19 |
| 1.27 | end of lifehigh | 1.27.7 | 2024-06-29 | 2024-07-26 |
| 1.26 | end of lifehigh | 1.26.8 | 2024-04-04 | 2024-04-18 |
| 1.25 | end of lifehigh | 1.25.11 | 2023-10-17 | 2024-01-18 |
| 1.24 | end of lifehigh | 1.24.12 | 2023-10-16 | 2023-10-19 |
| 1.23 | end of lifehigh | 1.23.12 | 2023-07-25 | 2023-07-15 |
| 1.22 | end of lifehigh | 1.22.11 | 2023-04-12 | 2023-04-15 |
| 1.21 | end of lifehigh | 1.21.6 | 2022-11-29 | 2023-01-12 |
| 1.20 | end of lifehigh | 1.20.7 | 2022-07-21 | 2022-10-05 |
| 1.19 | end of lifehigh | 1.19.5 | 2022-06-09 | 2022-07-14 |
| 1.18 | end of lifehigh | 1.18.6 | 2022-02-22 | 2022-04-15 |
| 1.17 | end of lifehigh | 1.17.4 | 2021-08-24 | 2022-01-11 |
| 1.16 | end of lifehigh | 1.16.5 | 2021-08-24 | 2021-10-08 |
| 1.15 | end of lifehigh | 1.15.5 | 2021-05-11 | 2021-07-07 |
| 1.14 | end of lifehigh | 1.14.7 | 2021-04-15 | 2021-04-08 |
| 1.13 | end of lifehigh | 1.13.8 | 2021-01-19 | 2021-01-20 |
| 1.12 | end of lifehigh | 1.12.7 | 2020-09-29 | 2020-11-01 |
| 1.11 | end of lifehigh | 1.11.2 | 2019-10-08 | 2020-07-11 |
| 1.10 | end of lifehigh | 1.10.0 | 2019-04-05 | 2020-04-05 |
| 1.9 | end of lifehigh | 1.9.1 | 2019-04-05 | 2019-12-20 |
| 1.8 | end of lifehigh | 1.8.0 | 2018-10-04 | 2019-10-04 |
| 1.7 | end of lifehigh | 1.7.1 | 2018-08-04 | 2019-06-21 |
| 1.6 | end of lifehigh | 1.6.0 | 2018-03-20 | 2019-03-20 |
| 1.5 | end of lifehigh | 1.5.0 | 2017-12-05 | 2018-12-05 |
| 1.4 | end of lifehigh | 1.4.0 | 2017-08-24 | 2018-08-24 |
| 1.3 | end of lifehigh | 1.3.0 | 2017-05-17 | 2018-05-17 |
| 1.2 | end of lifehigh | 1.2.0 | 2017-03-07 | 2018-03-07 |
| 1.1 | end of lifehigh | 1.1.0 | 2016-11-30 | 2017-11-30 |
| 1.0 | end of lifehigh | 1.0.0 | 2016-09-12 | 2017-09-12 |
