Istio

Istio

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 10.03.2026 22:16:21
  • Zuletzt bearbeitet 18.03.2026 18:58:59

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain mul...

  • EPSS 0.05%
  • Veröffentlicht 10.03.2026 22:16:21
  • Zuletzt bearbeitet 18.03.2026 18:59:40

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the...

  • EPSS 0.04%
  • Veröffentlicht 15.01.2026 19:18:50
  • Zuletzt bearbeitet 14.02.2026 18:16:10

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Warnung Medienbericht Exploit
  • EPSS 94.39%
  • Veröffentlicht 10.10.2023 14:15:10
  • Zuletzt bearbeitet 07.11.2025 19:00:41

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • EPSS 0.06%
  • Veröffentlicht 10.11.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:18:11

Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. ...

  • EPSS 0.68%
  • Veröffentlicht 13.10.2022 23:15:11
  • Zuletzt bearbeitet 21.11.2024 07:17:56

Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing er...

  • EPSS 0.31%
  • Veröffentlicht 09.06.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:46

Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most l...

  • EPSS 0.41%
  • Veröffentlicht 10.03.2022 21:15:14
  • Zuletzt bearbeitet 21.11.2024 06:50:57

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which resu...

  • EPSS 0.68%
  • Veröffentlicht 22.02.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:48:59

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which re...

  • EPSS 0.23%
  • Veröffentlicht 19.01.2022 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:45:15

Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE` permission for `gateways.gateway.networking.k8s.io` objects can escala...