v1.9.3

Date: October 3, 2026

Breaking changes

Security updates

  • Bumped Envoy to 1.39.2 to address CVE-2026-35189, a BoringSSL excessive memory allocation when parsing certificates with nameRelativeToCRLIssuer CRL Distribution Points that could be exploited for remote denial of service during TLS handshakes. Refer to the Envoy v1.39.2 release notes for details.

New features

Bug fixes

  • Fixed the shutdown-manager failing to create /tmp/shutdown-ready (breaking graceful shutdown and delaying proxy pod termination by the full grace period) when the Envoy container’s securityContext sets readOnlyRootFilesystem: true, by mounting a writable emptyDir at /tmp on the shutdown-manager.
  • Fixed obsolete resource snapshots being retained by the backing array of coalesced subscription updates.

Performance improvements

Deprecations

Other changes


Last modified October 3, 2026: add release note for v1.9.3 (ea60685c8)