Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Istio HIGH 7.7
CVE-2026-41413

Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is…

Fix: 1.28.6 / 1.29.2+
Fix from $1,950 2026-05-07
Istio MEDIUM 5.4
CVE-2026-39350

Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1,…

Fix: 1.27.9 / 1.28.6+
Fix from $1,600 2026-04-15
Istio HIGH 7.5
CVE-2026-31837

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS …

Fix: 1.27.8 / 1.28.5+
Fix from $1,950 2026-03-10
Istio MEDIUM 5.3
CVE-2026-31838

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header mat…

Fix: 1.27.8 / 1.28.5+
Fix from $1,600 2026-03-10
Istio HIGH 7.5
CVE-2022-39278

Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions …

Fix: 1.13.9 / 1.14.5+
Fix from $1,950 2022-10-13
Istio CRITICAL 9.8
CVE-2022-31045

Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configuratio…

Fix: 1.12.8 / 1.13.5+
Fix from $2,300 2022-06-09
Istio HIGH 7.5
CVE-2022-24726

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a requ…

Fix: 1.11.8 / 1.12.5+
Fix from $1,950 2022-03-10
Istio HIGH 7.5
CVE-2022-23635

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a re…

Fix: 1.11.7 / 1.12.4+
Fix from $1,950 2022-02-22
Istio CRITICAL 9.8
CVE-2022-21679

Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts m…

No fix yet
Fix from $2,300 2022-01-19
Istio HIGH 8.8
CVE-2022-21701

Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation a…

Mitigation only
Fix from $1,950 2022-01-19
Istio HIGH 7.5
CVE-2021-39156

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a…

Fix: 1.9.8 / 1.10.3+
Fix from $1,950 2021-08-24
Istio HIGH 7.5
CVE-2021-39155

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a…

Fix: 1.9.8 / 1.10.4+
Fix from $1,950 2021-08-24
Istio HIGH 8.8
CVE-2021-34824

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and Destination…

Fix: 1.9.6 / 1.10.2+
Fix from $1,950 2021-06-29
Istio CRITICAL 9.8
CVE-2021-31921

Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in th…

Fix: 1.8.6 / 1.9.5+
Fix from $2,300 2021-06-02
Istio MEDIUM 6.5
CVE-2021-31920

Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash …

Fix: 1.8.6 / 1.9.5+
Fix from $1,600 2021-05-27
Istio MEDIUM 6.8
CVE-2020-16844

In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffix…

Fix: after 1.6.7
Fix from $1,600 2020-10-01
Istio HIGH 7.5
CVE-2020-10739

Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: by sending a specially crafte…

Fix: 1.4.9 / 1.5.4+
Fix from $1,950 2020-06-02
Istio HIGH 7.4
CVE-2020-8843

An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Ist…

Fix: after 1.3.6
Fix from $1,950 2020-02-14
Istio HIGH 7.5
CVE-2019-18817

Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related issue to CVE-2019-18836.

Fix: 1.3.5+
Fix from $1,950 2019-11-12
Istio HIGH 7.5
CVE-2019-14993

Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, Virtua…

Fix: 1.1.13 / 1.2.4+
Fix from $1,950 2019-08-13
Istio HIGH 7.5
CVE-2019-12995

Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy. This is related to a jwt_authenticator.c…

Fix: 1.2.2+
Fix from $1,950 2019-06-28
Istio HIGH 7.5
CVE-2019-12243

Istio 1.1.x through 1.1.6 has Incorrect Access Control.

Fix: after 1.1.6
Fix from $1,950 2019-06-05