You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
July 29, 2026
For the clusters using TRAFFIC_DIRECTOR implementation,
IP auto-allocation
with DNS Proxy is now supported in Rapid release channel.
July 24, 2026
The Envoy Compressor Filter is now GA in the stable release channel.
July 21, 2026
The Envoy Lua Filter is now available as a preview feature in the stable release channel.
July 15, 2026
1.29.5-asm.12 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.5-asm.12 uses Envoy v1.35.13.
Patch 1.29.5-asm.12 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-46595 | Yes | Yes | Yes | Yes | Critical (10.0) |
| CVE-2026-8376 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-8925 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-39830 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39831 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39832 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39833 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39834 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-42496 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-42508 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-8924 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-8927 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8286 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2025-69720 | Yes | Yes | No | Yes | Low (7.8) |
| CVE-2026-39822 | Yes | Yes | Yes | Yes | High (7.8) |
| CVE-2026-39829 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-41992 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-46597 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-9547 | Yes | Yes | No | Yes | Low (7.4) |
| CVE-2026-25680 | Yes | Yes | Yes | Yes | Medium (6.5) |
| CVE-2026-39827 | Yes | Yes | Yes | Yes | Medium (6.5) |
| CVE-2026-8458 | Yes | Yes | No | Yes | Low (6.5) |
| CVE-2026-39828 | Yes | Yes | Yes | Yes | Medium (6.3) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-58055 | Yes | Yes | No | Yes | Medium (5.4) |
| CVE-2026-39835 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-42505 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-46598 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-41991 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-45582 | Yes | Yes | No | Yes | Medium (0.0) |
1.28.10-asm.4 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.10-asm.4 uses Envoy v1.36.9.
Patch 1.28.10-asm.4 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-8376 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-8925 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-42496 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8924 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-8927 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8286 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2025-69720 | Yes | Yes | No | Yes | Low (7.8) |
| CVE-2026-39822 | Yes | Yes | Yes | Yes | High (7.8) |
| CVE-2026-41992 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-42151 | No | No | No | Yes | High (7.5) |
| CVE-2026-42154 | No | No | No | Yes | High (7.5) |
| CVE-2026-9547 | Yes | Yes | No | Yes | Low (7.4) |
| CVE-2026-8458 | Yes | Yes | No | Yes | Low (6.5) |
| CVE-2026-40179 | No | No | No | Yes | Medium (6.1) |
| CVE-2026-44903 | No | No | No | Yes | Medium (6.1) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-58055 | Yes | Yes | No | Yes | Medium (5.4) |
| CVE-2026-42505 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-41991 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-45582 | Yes | Yes | No | Yes | Medium (0.0) |
1.27.9-asm.15 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.15 uses Envoy v1.35.13v.
Patch 1.27.9-asm.15 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-8376 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-8925 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-42496 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8924 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-8927 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8286 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2025-69720 | Yes | Yes | No | Yes | Low (7.8) |
| CVE-2026-39822 | Yes | Yes | Yes | Yes | High (7.8) |
| CVE-2026-41992 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-9547 | Yes | Yes | No | Yes | Low (7.4) |
| CVE-2026-8458 | Yes | Yes | No | Yes | Low (6.5) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-58055 | Yes | Yes | No | Yes | Medium (5.4) |
| CVE-2026-42505 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-41991 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-45582 | Yes | Yes | No | Yes | Medium (0.0) |
July 06, 2026
The Envoy Compressor Filter is now GA in the regular release channel.
The Envoy Lua Filter is now available as a preview feature in the regular release channel.
June 29, 2026
1.29.5-asm.5 is now available for in-cluster Cloud Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2026-045.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.5-asm.5 uses Envoy v1.37.5.
1.28.9-asm.4 is now available for in-cluster Cloud Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2026-045.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.9-asm.4 uses Envoy v1.36.9.
1.27.9-asm.9 is now available for in-cluster Cloud Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2026-045.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.9 uses Envoy v1.35.13.
Proxy version csm_mesh_proxy.csm_mesh_proxy.20260624e_RC01 for Gateway API on GKE clusters is rolling out to all Managed Cloud Service Mesh release channels over the next week.
This patch release contains the fixes for the security vulnerabilities listed in GCP-2026-040.
June 23, 2026
The following images are now rolling out for managed Cloud Service Mesh:
- Sidecar version 1.21.6-asm.38, is rolling out to the rapid release channel.
- Sidecar version 1.20.8-asm.88 is rolling out to the regular release channel.
- Sidecar version 1.19.10-asm.78 is rolling out to the stable release channel.
These patch releases contain the fix for the vulnerability listed in GCP-2026-040.
These rollouts will preempt those previously announced on June 12, 2026.
1.29.5-asm.3 is now available for in-cluster Cloud Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2026-040.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.5-asm.3 uses Envoy v1.37.5-dev.
This patch release also contain the fixes for the following CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-34182 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-45447 | Yes | Yes | No | Yes | High (8.8) |
| CVE-2026-7383 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2026-34180 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-45445 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-9076 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-42766 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-42767 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-34743 | Yes | Yes | No | Yes | Low (5.3) |
| CVE-2026-45446 | Yes | Yes | No | Yes | Low (4.8) |
| CVE-2026-42770 | Yes | Yes | No | Yes | Low (3.7) |
| CVE-2026-40226 | Yes | Yes | No | Yes | Medium (0.0) |
1.28.9-asm.2 is now available for in-cluster Cloud Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2026-040.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.9-asm.2 uses Envoy v1.36.9-dev.
This patch release also contain the fixes for the following CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-34182 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-45447 | Yes | Yes | No | Yes | High (8.8) |
| CVE-2026-7383 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2026-34180 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-45445 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-9076 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-42766 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-42767 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-34743 | Yes | Yes | No | Yes | Low (5.3) |
| CVE-2026-45446 | Yes | Yes | No | Yes | Low (4.8) |
| CVE-2026-42770 | Yes | Yes | No | Yes | Low (3.7) |
| CVE-2026-40226 | Yes | Yes | No | Yes | Medium (0.0) |
1.27.9-asm.8 is now available for in-cluster Cloud Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2026-040.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.8 uses Envoy v1.35.13-dev.
This patch release also contain the fixes for the following CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-34182 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-45447 | Yes | Yes | No | Yes | High (8.8) |
| CVE-2026-7383 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2026-34180 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-45445 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-9076 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-42766 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-42767 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-34743 | Yes | Yes | No | Yes | Low (5.3) |
| CVE-2026-45446 | Yes | Yes | No | Yes | Low (4.8) |
| CVE-2026-42770 | Yes | Yes | No | Yes | Low (3.7) |
| CVE-2026-40226 | Yes | Yes | No | Yes | Medium (0.0) |
June 22, 2026
The Envoy Lua Filter is now available as a preview feature in the rapid release channel.
June 15, 2026
The Envoy Compressor Filter is now GA in the rapid release channel.
To ensure your EnvoyFilter compressor configuration is fully supported, see
Modernize EnvoyFilter compressor configurations.
June 12, 2026
The following images are now rolling out for managed Cloud Service Mesh:
- Sidecar version 1.21.6-asm.36, is rolling out to the rapid release channel.
- Sidecar version 1.20.8-asm.86 is rolling out to the regular release channel.
- Sidecar version 1.19.10-asm.76 is rolling out to the stable release channel.
These rollouts will preempt those previously announced on June 3, 2026.
These patch releases contain the fix for the vulnerability listed in GCP-2026-035
Proxy version csm_mesh_proxy.20260423_RC03 for Gateway API on GKE clusters is rolling out to all Managed Cloud Service Mesh release channels over the next week.
June 09, 2026
1.29.4-asm.0 is now available for in-cluster Cloud Service Mesh.
You can now download 1.29.4-asm.0 for in-cluster Cloud Service Mesh. It includes the features of Istio 1.29.4 subject to the list of supported features.
The following environment variables, labels, and annotations are not supported:
PILOT_IGNORE_RESOURCESandPILOT_INCLUDE_RESOURCESRetryIgnorePreviousHostsomit_empty_valuesPILOT_SPAWN_UPSTREAM_SPAN_FOR_GATEWAYMAX_CONNECTIONS_PER_SOCKET_EVENT_LOOPwith the value 1PILOT_DNS_JITTER_DURATIONPILOT_DNS_JITTER_DURATIONENABLE_NATIVE_SIDECARSwith the value truePILOT_IP_AUTOALLOCATE_IPV4_PREFIXandPILOT_IP_AUTOALLOCATE_IPV6_PREFIXPILOT_DNS_CARES_UDP_MAX_QUERIESENABLE_WILDCARD_HOST_SERVICE_ENTRIES_FOR_TLS- 'BLOCKED_CIDRS_IN_JWKS_URIS`
ENABLE_DEBUG_ENDPOINT_AUTHDISABLE_TRACK_REMAINING_CB_METRICSgateway.istio.io/tls-cipher-suitesfileFlushMinSizeKBandfileFlushIntervalsettings in ProxyConfigtopology.istio.io/localitystatsCompressionProxyConfig optionproxy.istio.io/configannotation for metric compression overrides
Istio's experimental feature to enable lazy subset creation of envoy statistics is not supported.
The formatter option within the spec.tracing[].customTags field of the
Telemetry custom resource (telemetry.istio.io) is unsupported.
The istiod_remote_cluster_sync_status Prometheus gauge metric, exposed on the
Istiod control plane metrics endpoint (port 15014 /metrics), is not
supported.
The following are unsupported for proxyless gRPC clients:
Configuring the
LEAST_REQUESTload balancing policy within thespec.trafficPolicy.loadBalancer.simplefield of a DestinationRule custom resource (networking.istio.io)Configuring the
http2MaxRequestscircuit breaker within thespec.trafficPolicy.connectionPool.http.http2MaxRequestsfield of a DestinationRule custom resource (networking.istio.io)
The ENABLE_AUTO_SNI flag is still supported to keep aligned with the legacy
behavior.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh version 1.29.4-asm.0 uses Envoy v1.37.4-dev.
In-cluster Cloud Service Mesh 1.26 is no longer supported. For more information and to view the earliest end-of-life dates for other versions, see Supported versions.
June 08, 2026
The rollouts previously announced on June 3, 2026 have been stopped. The following release will supersede them and include those patches and the fix for the vulnerability listed in GCP-2026-035.
1.28.7-asm.4 is now available for in-cluster Cloud Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2026-035.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.7-asm.4 uses Envoy v1.36.8-dev.
1.27.9-asm.5 is now available for in-cluster Cloud Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2026-035.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.5 uses Envoy v1.35.12-dev.
1.26.8-asm.11 is now available for in-cluster Cloud Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2026-035.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.26.8-asm.11 uses Envoy v1.34.14.
June 03, 2026
The following images are now rolling out for managed Cloud Service Mesh:
- 1.21.6-asm.32 is rolling out to the rapid release channel.
- The regular release channel is being upgraded from 1.20 to 1.21.6-asm.32.
- The stable release channel is being upgraded from 1.19 to 1.20.8-asm.80.
These patch releases contain the fixes for the following CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-27143 | Yes | Yes | Yes | Yes | Critical (9.8) |
| CVE-2026-31789 | Yes | Yes | No | Yes | Low (9.8) |
| CVE-2026-27140 | Yes | Yes | Yes | Yes | High (8.8) |
| CVE-2026-28387 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2026-41413 | Yes | Yes | Yes | Yes | Medium (7.7) |
| CVE-2026-2219 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-27135 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-28388 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-28389 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-28390 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-29181 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-31790 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-32280 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-32281 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-32283 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-33811 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-33814 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-34986 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-39820 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-39836 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-4046 | No | No | Yes | No | High (7.5) |
| CVE-2026-42499 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-42501 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-4437 | No | No | Yes | No | High (7.5) |
| CVE-2026-5773 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-6276 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-27144 | Yes | Yes | Yes | Yes | High (7.1) |
| CVE-2026-39883 | Yes | Yes | Yes | Yes | High (7.0) |
| CVE-2026-4878 | Yes | Yes | No | Yes | Medium (7.0) |
| CVE-2026-5545 | Yes | Yes | No | Yes | Medium (6.5) |
| CVE-2026-32282 | Yes | Yes | Yes | Yes | Medium (6.4) |
| CVE-2026-32289 | Yes | Yes | Yes | Yes | Medium (6.1) |
| CVE-2026-39823 | Yes | Yes | Yes | Yes | Medium (6.1) |
| CVE-2026-39826 | Yes | Yes | Yes | Yes | Medium (6.1) |
| CVE-2026-39817 | Yes | Yes | Yes | Yes | Medium (5.9) |
| CVE-2026-4873 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-6253 | Yes | Yes | No | Yes | Medium (5.9) |
| CVE-2026-32288 | Yes | Yes | Yes | Yes | Medium (5.5) |
| CVE-2026-39350 | Yes | Yes | Yes | Yes | Medium (5.4) |
| CVE-2026-4438 | No | No | Yes | No | Medium (5.4) |
| CVE-2026-39819 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-39825 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-6429 | Yes | Yes | No | Yes | Medium (5.3) |
| CVE-2026-7168 | Yes | Yes | No | Yes | Medium (5.3) |
| CVE-2026-35469 | No | Yes | No | Yes | High (0.0) |
| CVE-2026-5958 | Yes | Yes | No | Yes | Medium (0.0) |
1.28.7-asm.3 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.7-asm.3 uses Envoy v1.36.7-dev.
Patch 1.28.7-asm.3 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-27143 | Yes | Yes | Yes | Yes | Critical (9.8) |
| CVE-2026-31789 | Yes | Yes | No | Yes | Low (9.8) |
| CVE-2026-27140 | Yes | Yes | Yes | Yes | High (8.8) |
| CVE-2026-28387 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2026-41413 | Yes | Yes | Yes | Yes | Medium (7.7) |
| CVE-2026-2219 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-27135 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-28388 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-28389 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-28390 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-29181 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-31790 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-32280 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-32281 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-32283 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-33811 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-33814 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-34986 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-39820 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-39836 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-4046 | No | No | Yes | No | High (7.5) |
| CVE-2026-42499 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-42501 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-4437 | No | No | Yes | No | High (7.5) |
| CVE-2026-5773 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-6276 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-27144 | Yes | Yes | Yes | Yes | High (7.1) |
| CVE-2026-39883 | Yes | Yes | Yes | Yes | High (7.0) |
| CVE-2026-4878 | Yes | Yes | No | Yes | Medium (7.0) |
| CVE-2026-5545 | Yes | Yes | No | Yes | Medium (6.5) |
| CVE-2026-32282 | Yes | Yes | Yes | Yes | Medium (6.4) |
| CVE-2026-32289 | Yes | Yes | Yes | Yes | Medium (6.1) |
| CVE-2026-39823 | Yes | Yes | Yes | Yes | Medium (6.1) |
| CVE-2026-39826 | Yes | Yes | Yes | Yes | Medium (6.1) |
| CVE-2026-39817 | Yes | Yes | Yes | Yes | Medium (5.9) |
| CVE-2026-4873 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-6253 | Yes | Yes | No | Yes | Medium (5.9) |
| CVE-2026-32288 | Yes | Yes | Yes | Yes | Medium (5.5) |
| CVE-2026-39350 | Yes | Yes | Yes | Yes | Medium (5.4) |
| CVE-2026-4438 | No | No | Yes | No | Medium (5.4) |
| CVE-2026-39819 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-39825 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-6429 | Yes | Yes | No | Yes | Medium (5.3) |
| CVE-2026-7168 | Yes | Yes | No | Yes | Medium (5.3) |
| CVE-2026-35469 | No | Yes | No | Yes | High (0.0) |
| CVE-2026-5958 | Yes | Yes | No | Yes | Medium (0.0) |
1.27.9-asm.4 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.4 uses Envoy v1.35.10-dev.
Patch 1.27.9-asm.4 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2022-31045 | Yes | Yes | Yes | Yes | Medium (9.8) |
| CVE-2026-27143 | Yes | Yes | Yes | Yes | Critical (9.8) |
| CVE-2026-31789 | Yes | Yes | No | Yes | Low (9.8) |
| CVE-2026-27140 | Yes | Yes | Yes | Yes | High (8.8) |
| CVE-2026-28387 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2026-41413 | Yes | Yes | Yes | Yes | Medium (7.7) |
| CVE-2019-14993 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2021-39155 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2021-39156 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2022-23635 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-2219 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-27135 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-28388 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-28389 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-28390 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-29181 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-31790 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-32280 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-32281 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-32283 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-33811 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-33814 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-34986 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-39820 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-39836 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-4046 | No | No | Yes | No | High (7.5) |
| CVE-2026-42499 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-42501 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-4437 | No | No | Yes | No | High (7.5) |
| CVE-2026-5773 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-6276 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-27144 | Yes | Yes | Yes | Yes | High (7.1) |
| CVE-2026-39883 | Yes | Yes | Yes | Yes | High (7.0) |
| CVE-2026-4878 | Yes | Yes | No | Yes | Medium (7.0) |
| CVE-2026-5545 | Yes | Yes | No | Yes | Medium (6.5) |
| CVE-2026-32282 | Yes | Yes | Yes | Yes | Medium (6.4) |
| CVE-2026-32289 | Yes | Yes | Yes | Yes | Medium (6.1) |
| CVE-2026-39823 | Yes | Yes | Yes | Yes | Medium (6.1) |
| CVE-2026-39826 | Yes | Yes | Yes | Yes | Medium (6.1) |
| CVE-2026-39817 | Yes | Yes | Yes | Yes | Medium (5.9) |
| CVE-2026-4873 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-6253 | Yes | Yes | No | Yes | Medium (5.9) |