Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.7
CVE-2026-41413
Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is…
Istio
1.28.6 / 1.29.2+
MEDIUM 5.4
CVE-2026-39350
Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1,…
Istio
1.27.9 / 1.28.6+
HIGH 7.5
CVE-2026-31837
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS …
Istio
1.27.8 / 1.28.5+
MEDIUM 5.3
CVE-2026-31838
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header mat…
Istio
1.27.8 / 1.28.5+
HIGH 7.5
CVE-2022-39278
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions …
Istio
1.13.9 / 1.14.5+
CRITICAL 9.8
CVE-2022-31045
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configuratio…
Istio
1.12.8 / 1.13.5+
HIGH 7.5
CVE-2022-24726
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a requ…
Istio
1.11.8 / 1.12.5+
HIGH 7.5
CVE-2022-23635
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a re…
Istio
1.11.7 / 1.12.4+
CRITICAL 9.8
CVE-2022-21679
Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts m…
Istio
No fix yet
HIGH 8.8
CVE-2022-21701
Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation a…
Istio
Mitigation only
HIGH 7.5
CVE-2021-39156
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a…
Istio
1.9.8 / 1.10.3+
HIGH 7.5
CVE-2021-39155
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a…
Istio
1.9.8 / 1.10.4+
HIGH 8.8
CVE-2021-34824
Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and Destination…
Istio
1.9.6 / 1.10.2+
CRITICAL 9.8
CVE-2021-31921
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in th…
Istio
1.8.6 / 1.9.5+
MEDIUM 6.5
CVE-2021-31920
Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash …
Istio
1.8.6 / 1.9.5+
MEDIUM 6.8
CVE-2020-16844
In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffix…
Istio
after 1.6.7
HIGH 7.5
CVE-2020-10739
Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: by sending a specially crafte…
Istio
1.4.9 / 1.5.4+
HIGH 7.4
CVE-2020-8843
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Ist…
Istio
after 1.3.6
HIGH 7.5
CVE-2019-18817
Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related issue to CVE-2019-18836.
Istio
1.3.5+
HIGH 7.5
CVE-2019-14993
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, Virtua…
Istio
1.1.13 / 1.2.4+
HIGH 7.5
CVE-2019-12995
Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy. This is related to a jwt_authenticator.c…
Istio
1.2.2+
HIGH 7.5
CVE-2019-12243
Istio 1.1.x through 1.1.6 has Incorrect Access Control.
Istio
after 1.1.6