CVE-2026-41413
- EPSS 0.06%
- Veröffentlicht 07.05.2026 04:18:32
- Zuletzt bearbeitet 08.05.2026 17:03:51
Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is created with a jwksUri pointing to an internal service, istiod makes an unauthenticated HTTP GET req...
CVE-2026-39350
- EPSS 0.01%
- Veröffentlicht 15.04.2026 22:42:24
- Zuletzt bearbeitet 23.04.2026 20:00:21
Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1, the serviceAccounts and notServiceAccounts fields in AuthorizationPolicy incorrectly interpret dots ...
CVE-2026-31838
- EPSS 0.04%
- Veröffentlicht 10.03.2026 22:16:21
- Zuletzt bearbeitet 07.04.2026 03:16:07
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain mul...
CVE-2026-31837
- EPSS 0.05%
- Veröffentlicht 10.03.2026 22:16:21
- Zuletzt bearbeitet 18.03.2026 18:59:40
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the...
CVE-2026-23766
- EPSS 0.04%
- Veröffentlicht 15.01.2026 19:18:50
- Zuletzt bearbeitet 14.02.2026 18:16:10
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2023-44487
- EPSS 94.4%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 12.05.2026 15:10:32
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-39388
- EPSS 0.06%
- Veröffentlicht 10.11.2022 20:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:11
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. ...
CVE-2022-39278
- EPSS 0.72%
- Veröffentlicht 13.10.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 07:17:56
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing er...
CVE-2022-31045
- EPSS 0.43%
- Veröffentlicht 09.06.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 07:03:46
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most l...
CVE-2022-24726
- EPSS 0.41%
- Veröffentlicht 10.03.2022 21:15:14
- Zuletzt bearbeitet 21.11.2024 06:50:57
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which resu...