Aug 24, 2026 — App & API Protector Hybrid: Protector v1.6.1
1 day ago
This release introduces Protector v1.6.1, featuring a critical security upgrade and an important bug fix for client IP visibility:
- The HTTP/2 memory exhaustion vulnerability (CVE-2026-47774, CVSS 7.5 HIGH) is now resolved. Upgrading the Envoy proxy component to version 1.39.0 mitigates a high-severity vulnerability that could lead to denial-of-service (DoS) conditions. To optimize memory allocation, this updated Envoy version introduces proper validation for cookie header bytes and strictly enforces limits on the total decoded header size.
- Client IP forwarding accuracy on Envoy-based deployments is now restored. The Lua plugin now automatically forwards the correct client IP header when it is missing from original request headers across all Envoy-based environments (including Envoy Gateway, Istio Ingress Gateway, OpenShift Service Mesh, OpenShift Envoy Gateway, and Reverse Proxy deployments) ensuring consistent client IP visibility without requiring any manual configuration changes.
