So Envoy Proxy put v1.39.2 on the feed, dated October 1, 2026. We flagged it Important as a security fix. Recency wants the calm opener: patch tag, BoringSSL bump, Debian packaging cleanup, refreshed Ubuntu and distroless images. Fine. Those are the lines people paste into a mesh channel when they skim a proxy release.
The line that matters, to the best of my understanding, is CVE-2026-35189. BoringSSL was updated because parsing X.509 certificates that carry CRL Distribution Points with nameRelativeToCRLIssuer entries could allocate hundreds of MiB of heap from a single cert that still fits under the normal per-certificate size limit. That path is reachable during TLS handshakes. A remote peer that can present a crafted cert can push Envoy into a denial of service without needing a huge payload. The unused nameRelativeToCRLIssuer processing was removed.
That is the partner ticket shape. Someone already thought "we terminate TLS at the edge, cert size limits protect us." Then handshake workers start chewing memory, and the prior cert-size story is not enough. 1.39.2 closes the parse path. Scope is Envoy installs that accept TLS from untrusted or semi-trusted peers (ingress, mesh gateways, mTLS to outside). If every peer is fully under your control and you never handshake against attacker-influenced certs, this specific path is quieter. If you terminate public or partner TLS on Envoy, treat the handshake DoS as the reason this patch is not optional.
What operators should check first is not the Docker tag on the release page. It is which Envoy binaries still sit in front of handshakes you do not fully control. Edge ingress, gateway pods that accept partner mTLS, and any sidecar that presents a listener to the public internet are the obvious ones. Internal east-west only fleets still matter if a compromised workload can open a TLS connection to a neighbor and feed it a crafted cert. The release notes do not publish a CVSS score here, and we are not inventing one. The practical claim from the vendor note is enough: excessive heap allocation during certificate parse, remote DoS via TLS handshakes, fixed by removing the unused relative-name CRL DP processing in BoringSSL.
The same security train landed on sibling backports the same day: v1.38.5, v1.37.7, and related 1.36.x packaging. Kind of easy to file only the newest minor and leave a fleet on 1.38. Kind of useless when the open question is "are our edge proxies still parsing that CRL DP form." Pin the line you run, then confirm the backport tag that carries CVE-2026-35189. Chart bumps and image digests lag. The talking point for a status call is the CVE id plus the minor line you are on, not "we are close to 1.39."
There is a packaging aside in the same note that is easy to over-paste. Debian bullseye (11) packaging is removed. Bullseye LTS ended 31 August 2026, and the main mirrors no longer carry its repos, so bullseye .deb packages are no longer built or published. Ubuntu build and distroless Docker base images were refreshed. That matters if your install path still pulls bullseye debs or pins an old distroless digest expecting the previous base. It is not the hero. The hero is the handshake memory blow-up.
I keep almost filing Envoy under "data-plane patch train, ignore until the mesh chart bumps." Kind of the wrong habit when you sell into teams that put Envoy in front of partner traffic and treat cert size limits as a hard stop. Tracking product change here means reading past the packaging cleanup and asking which line changes a partner ticket. Let's say the talking point is not "1.39.2 shipped a BoringSSL bump." It is cert parsing with nameRelativeToCRLIssuer CRL Distribution Points could allocate excessive heap during TLS handshakes (CVE-2026-35189), and 1.39.2 plus the 1.38.5 / 1.37.7 backports close that path, then yes mention bullseye debs are gone. We pull it into a uniform entry shape at /sources/envoy.releases and /sources/envoy-proxy.updates. Same JSON as everything else. Recency still wants the patch tag. Recency is not the cert-parsing DoS.
Official notes: Envoy 1.39.2 version history. Full changelog: v1.39.1...v1.39.2.