Security & Maintenance: the v0.32 Patch Releases

June 16, 2026
Share on Bluesky

Beyond the v0.32.0 feature release, the v0.32 line received a steady stream of patch releases focused on security and stability. Most notably, Envoy was updated several times to address CVEs, and a handful of session and configuration fixes landed. If you're on v0.32, staying current on patches is the easiest way to pick these up.

Highlights:

  • Envoy security updates – v0.32.3 moved to Envoy v1.36.5 to address five CVEs (CVE-2026-26308 through CVE-2026-26311 and CVE-2026-26330), and v0.32.9 moved to Envoy v1.36.8 to address CVE-2026-47774.

  • Additional security fixes – v0.32.8 includes a fix for advisory GHSA-ggw3-5987-rx77, and v0.32.2 shipped the MCP message-smuggling fix (MCP Go SDK v1.3.1).

  • Session & header handling – v0.32.6 removed exp and nbf from core sessions, and v0.32.9 increased Envoy header size limits to better handle large headers.

  • Reliability fixes – v0.32.2 limited the sync cache batch size to 128MB (avoiding Pebble's 4GB batch limit), v0.32.4 made autocert detect use_proxy_protocol changes on the HTTP redirect server, and v0.32.3 added a Databroker VersionedConfig proto and syncer.

  • Toolchain & dependency upkeep – Go was bumped through 1.25.9 (v0.32.5) and 1.25.10 (v0.32.7), alongside routine dependency updates across the 0.32 branch.

Share: Share on Bluesky

Get our product updates delivered directly to your inbox

Revolutionize
Your Security

Embrace Seamless Resource Access, Robust Zero Trust Integration, and Streamlined Compliance with Our App.