v1.4.5

Date: October 15, 2025

Security updates

  • Bumped golang to 1.24.9 to fix the crypto/x509 reggression.

Bug fixes

  • Added a check to ensure that per proxy xds snapshot cache references are cleaned up when the connection is closed.
  • Fixed an issue where use GRPCRoute with RequestMirror cause panic.
  • Fixed an issue where certificate SAN overlap detection in gateway listeners.
  • Disabled the default emission of x-envoy-ratelimited headers from the rate limit filter and re-enable with the enableEnvoyHeaders setting in ClientTrafficPolicy.

Other changes

  • Updated Envoy Proxy to v1.34.10.