Cloud Service Mesh release notes

This page contains release notes for each version of Cloud Service Mesh. You can periodically check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

September 01, 2026

Managed Cloud Service Mesh
Security

Managed Cloud Service Mesh will start using proxy version csm_mesh_proxy.20260819_RC00 for Gateway API on GKE clusters. This proxy version maps closest to Envoy version 1.37. This change is rolling out to all release channels and contains the fix for the managed Cloud Service Mesh security vulnerabilities listed in GCP-2026-057.

August 31, 2026

1.30.x
Announcement

1.30.4-asm.1 is now available for in-cluster Cloud Service Mesh.

You can now download 1.30.4-asm.1 for in-cluster Cloud Service Mesh. It includes the features of Istio 1.30.4 subject to the list of supported features.

The following are not supported:

  • Failover Priority support for DNS clusters
  • ENABLE_WILDCARD_HOST_SERVICE_ENTRIES_FOR_TLS
  • Multiple CUSTOM external authorization providers per workload
  • The DEBUG_ENDPOINT_AUTH_ALLOWED_NAMESPACES flag

For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh version 1.30.4-asm.1 uses Envoy v1.38.4-dev.

1.27.x
Announcement

In-cluster Cloud Service Mesh 1.27 is no longer supported. For more information and to view the earliest end-of-life dates for other versions, see Supported versions.

August 27, 2026

Managed Cloud Service Mesh
Security

The following images are now rolling out for managed Cloud Service Mesh:

  • 1.21.6-asm.71 is rolling out to the rapid release channel.
  • 1.20.8-asm.119 is rolling out to the regular release channel.
  • 1.19.10-asm.109 is rolling out to the stable release channel.

These versions resolve the security vulnerabilities listed in Security Bulletin GCP-2026-057.

August 26, 2026

1.29.x
Announcement

1.29.7-asm.2 is now available for in-cluster Cloud Service Mesh.

For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.7-asm.2 uses Envoy v1.35.14.

This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057.

1.29.x
Fixed

Patch 1.29.7-asm.2 contains the fix for the following platform CVEs:

CVE Proxy Control Plane Distroless CNI Severity
CVE-2026-5704 Yes Yes No Yes Medium (5.5)
1.28.x
Announcement

1.28.10-asm.24 is now available for in-cluster Cloud Service Mesh.

For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.10-asm.24 uses Envoy v1.36.10.

This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057.

1.28.x
Fixed

Patch 1.28.10-asm.24 contains the fix for the following platform CVEs:

CVE Proxy Control Plane Distroless CNI Severity
CVE-2026-5704 Yes Yes No Yes Medium (5.5)
1.27.x
Announcement

1.27.9-asm.34 is now available for in-cluster Cloud Service Mesh.

For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.34 uses Envoy v1.35.14.

This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057.

1.27.x
Fixed

Patch 1.27.9-asm.34 contains fixes for the following platform CVEs:

CVE Proxy Control Plane Distroless CNI Severity
CVE-2026-10536 Yes Yes No Yes Low (9.8)
CVE-2026-42151 No No No Yes High (7.5)
CVE-2026-42154 No No No Yes High (7.5)
CVE-2026-40179 No No No Yes Medium (6.1)
CVE-2026-44903 No No No Yes Medium (6.1)
CVE-2026-5704 Yes Yes No Yes Medium (5.5)
Managed Cloud Service Mesh
Feature

For clusters using the TRAFFIC_DIRECTOR implementation, configuring the trace sampling rate with randomSamplingPercentage with the Telemetry API is now supported in the Rapid release channel. For more information, see Accessing Cloud Trace.

August 20, 2026

Managed Cloud Service Mesh
Feature

The guidance for using proxy image types (default and distroless) with Managed Cloud Service Mesh has been updated:

  • Directly onboarded clusters using the TRAFFIC_DIRECTOR implementation use distroless proxy images by default, and other image types are not supported.
  • Migrated clusters (migrated from ISTIOD to TRAFFIC_DIRECTOR) default to default images, but can opt in to distroless images via MeshConfig or the sidecar.istio.io/proxyImageType: distroless Pod annotation.

For more information, see Distroless proxy images and Identify the proxy image type used in the cluster.

July 29, 2026

Managed Cloud Service Mesh
Feature

For the clusters using TRAFFIC_DIRECTOR implementation, IP auto-allocation with DNS Proxy is now supported in Rapid release channel.

July 24, 2026

Managed Cloud Service Mesh
Feature

The Envoy Compressor Filter is now GA in the stable release channel.

July 21, 2026

Managed Cloud Service Mesh
Feature

The Envoy Lua Filter is now available as a preview feature in the stable release channel.

July 15, 2026

1.29.x
Announcement

1.29.5-asm.12 is now available for in-cluster Cloud Service Mesh.

For details on upgrading Cloud Service Mesh, see