Skip to content

fix(deps): vuln github.com/envoyproxy/envoy (minor → v1.38.2) [golang-http/simple] - #22

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/go/simple/4-1781559317
Draft

fix(deps): vuln github.com/envoyproxy/envoy (minor → v1.38.2) [golang-http/simple]#22
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/go/simple/4-1781559317

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • golang-http/simple (go)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
github.com/envoyproxy/envoy v1.24.0 v1.38.2 minor Direct 2 HIGH, 12 MEDIUM, 2 LOW

Security Details

🚨 Critical & High Severity (2 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
github.com/envoyproxy/envoy GHSA-ghc4-35x6-crw5 HIGH Envoy has RBAC Header Validation Bypass via Multi-Value Header Concatenation v1.24.0 1.37.1
github.com/envoyproxy/envoy CVE-2026-26308 HIGH Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenation v1.24.0 -
ℹ️ Other Vulnerabilities (14)
Package CVE Severity Summary Unsafe Version Fixed In
github.com/envoyproxy/envoy GHSA-cf3q-gqg7-3fm9 MODERATE Envoy crashes when HTTP ext_proc processes local replies v1.24.0 1.30.10
github.com/envoyproxy/envoy CVE-2025-66220 MODERATE Envoy’s TLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null byte v1.24.0 -
github.com/envoyproxy/envoy CVE-2026-26310 MODERATE Crash for scoped ip address in Envoy during DNS v1.24.0 -
github.com/envoyproxy/envoy GHSA-3cw6-2j68-868p MODERATE Envoy vulnerable to crash for scoped ip address during DNS v1.24.0 -
github.com/envoyproxy/envoy GHSA-84xm-r438-86px MODERATE Envoy: HTTP - filter chain execution on reset streams causing UAF crash v1.24.0 -
github.com/envoyproxy/envoy CVE-2026-26311 MODERATE Envoy HTTP: filter chain execution on reset streams causing UAF crash v1.24.0 -
github.com/envoyproxy/envoy GHSA-rwjg-c3h2-f57p MODERATE Envoy's TLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null byte v1.24.0 1.36.3
github.com/envoyproxy/envoy CVE-2025-64527 MODERATE Envoy crashes when JWT authentication is configured with the remote JWKS fetching v1.24.0 -
github.com/envoyproxy/envoy GHSA-mp85-7mrq-r866 MODERATE Envoy crashes when JWT authentication is configured with the remote JWKS fetching v1.24.0 1.36.3
github.com/envoyproxy/envoy CVE-2026-26309 MODERATE Envoy has an off-by-one write in JsonEscaper::escapeString() v1.24.0 -
github.com/envoyproxy/envoy GHSA-56cj-wgg3-x943 MODERATE Envoy affected by off-by-one write in JsonEscaper::escapeString() v1.24.0 -
github.com/envoyproxy/envoy CVE-2025-30157 MODERATE Envoy crashes when HTTP ext_proc processes local replies v1.24.0 -
github.com/envoyproxy/envoy CVE-2025-64763 LOW Envoy forwards early CONNECT data in TCP proxy mode v1.24.0 -
github.com/envoyproxy/envoy GHSA-rj35-4m94-77jh LOW Envoy forwards early CONNECT data in TCP proxy mode v1.24.0 1.36.3
⚠️ Dependencies that have Reached EOL (1)
Dependency Unsafe Version EOL Date New Version Path
github.com/envoyproxy/envoy v1.24.0 Oct 19, 2025 v1.38.2 golang-http/simple/go.mod

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-prod-us1-4

datadog-prod-us1-4 Bot commented Jun 15, 2026

Copy link
Copy Markdown

Pipelines

Fix all issues with BitsAI

⚠️ Warnings

🚦 2 Pipeline jobs failed

Docs | docs   View in Datadog   GitHub Actions

Verify | verify   View in Datadog   GitHub Actions

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 1a0778f | Docs | Datadog PR Page | Give us feedback!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants