VYPR
High severity7.5NVD Advisory· Published Jun 2, 2020· Updated Jun 17, 2026

CVE-2020-10739

CVE-2020-10739

Description

Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: by sending a specially crafted packet, an attacker could trigger a Null Pointer Exception resulting in a Denial of Service. This could be sent to the ingress gateway or a sidecar, triggering a null pointer exception which results in a denial of service. This also affects servicemesh-proxy where a null pointer exception flaw was found in servicemesh-proxy. When running Telemetry v2 (not on by default in version 1.4.x), an attacker could send a specially crafted packet to the ingress gateway or proxy sidecar, triggering a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Range: 1.4.x before 1.4.9, 1.5.x before 1.5.4
  • Istio/Istiollm-fuzzy2 versions
    1.4.x before 1.4.9, 1.5.x before 1.5.4+ 1 more
    • (no CPE)range: 1.4.x before 1.4.9, 1.5.x before 1.5.4
    • cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*range: >=1.4.0,<1.4.9
  • Range: >= 1.4.0, < 1.4.9

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.