VYPR

Istio

by Istio

Source repositories

CVEs (28)

  • CVE-2026-31838MedMar 10, 2026
    risk 0.34cvss 5.3epss 0.00

    Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain multiple values. An attacker…

  • CVE-2022-21701MedJan 19, 2022
    risk 0.33cvss 5.0epss 0.01

    Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE` permission for `gateways.gateway.networking.k8s.io` objects can escalate this privilege to create…

  • CVE-2026-39350MedApr 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1, the serviceAccounts and notServiceAccounts fields in AuthorizationPolicy incorrectly interpret dots (.) as a regular expression…

  • CVE-2026-41413MedMay 7, 2026
    risk 0.26cvss 5.0epss 0.00

    Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is created with a jwksUri pointing to an internal service, istiod makes an unauthenticated HTTP GET request to that URL without…

  • CVE-2020-11767LowApr 15, 2020
    risk 0.20cvss 3.1epss 0.02

    Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured explicitly (e.g., abc.example.com) is sent to the server(s) listening behind…

  • CVE-2022-24726HigMar 10, 2022
    risk 0.00cvss 7.5epss 0.02

    Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane…

  • CVE-2019-12995HigJun 28, 2019
    risk 0.00cvss 7.5epss 0.02

    Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy. This is related to a jwt_authenticator.cc segmentation fault.

  • CVE-2019-12243HigJun 5, 2019
    risk 0.00cvss 7.5epss 0.01

    Istio 1.1.x through 1.1.6 has Incorrect Access Control.

Page 2 of 2