Istio 1.27.8 is a security-focused patch release addressing multiple CVEs. Key fixes include a high-severity JWKS resolver failure that could allow authentication bypass using known default keys (CVSS 8.7), a medium-severity cross-namespace proxy data access issue via debug endpoints (CVSS 6.9), a potential SSRF in WasmPlugin

2m read timeFrom istio.io
Post cover image
Table of contents
Envoy CVEsIstio CVEsIstio Security Fixes

Sort: