CVE-2026-31838
- EPSS 0.04%
- Veröffentlicht 10.03.2026 22:16:21
- Zuletzt bearbeitet 18.03.2026 18:58:59
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain mul...
CVE-2026-31837
- EPSS 0.05%
- Veröffentlicht 10.03.2026 22:16:21
- Zuletzt bearbeitet 18.03.2026 18:59:40
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the...
CVE-2026-23766
- EPSS 0.04%
- Veröffentlicht 15.01.2026 19:18:50
- Zuletzt bearbeitet 14.02.2026 18:16:10
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2023-44487
- EPSS 94.39%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 07.11.2025 19:00:41
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-39388
- EPSS 0.06%
- Veröffentlicht 10.11.2022 20:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:11
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. ...
CVE-2022-39278
- EPSS 0.68%
- Veröffentlicht 13.10.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 07:17:56
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing er...
CVE-2022-31045
- EPSS 0.31%
- Veröffentlicht 09.06.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 07:03:46
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most l...
CVE-2022-24726
- EPSS 0.41%
- Veröffentlicht 10.03.2022 21:15:14
- Zuletzt bearbeitet 21.11.2024 06:50:57
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which resu...
CVE-2022-23635
- EPSS 0.68%
- Veröffentlicht 22.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:59
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which re...
CVE-2022-21701
- EPSS 0.23%
- Veröffentlicht 19.01.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 06:45:15
Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE` permission for `gateways.gateway.networking.k8s.io` objects can escala...