Skip to main content

Changelog

Security & Maintenance: the v0.32 Patch Releases

Beyond the v0.32.0 feature release, the v0.32 line received a steady stream of patch releases focused on security and stability. Most notably, Envoy was updated several times to address CVEs, and a handful of session and configuration fixes landed. If you're on v0.32, staying current on patches is the easiest way to pick these up.

Beyond the v0.32.0 feature release, the v0.32 line received a steady stream of patch releases focused on security and stability. Most notably, Envoy was updated several times to address CVEs, and a handful of session and configuration fixes landed. If you're on v0.32, staying current on patches is the easiest way to pick these up.

Highlights:

  • Envoy security updates – v0.32.3 moved to Envoy v1.36.5 to address five CVEs (CVE-2026-26308 through CVE-2026-26311 and CVE-2026-26330), and v0.32.9 moved to Envoy v1.36.8 to address CVE-2026-47774.
  • Additional security fixes – v0.32.8 includes a fix for advisory GHSA-ggw3-5987-rx77, and v0.32.2 shipped the MCP message-smuggling fix (MCP Go SDK v1.3.1).
  • Session & header handling – v0.32.6 removed exp and nbf from core sessions, and v0.32.9 increased Envoy header size limits to better handle large headers.
  • Reliability fixes – v0.32.2 limited the sync cache batch size to 128MB (avoiding Pebble's 4GB batch limit), v0.32.4 made autocert detect use_proxy_protocol changes on the HTTP redirect server, and v0.32.3 added a Databroker VersionedConfig proto and syncer.
  • Toolchain & dependency upkeep – Go was bumped through 1.25.9 (v0.32.5) and 1.25.10 (v0.32.7), alongside routine dependency updates across the 0.32 branch.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo