Istio has disclosed security advisory ISTIO-SECURITY-2026-001 covering multiple CVEs in both Envoy and Istio. Key vulnerabilities include: a high-severity RBAC header matcher bypass in Envoy (CVSS 7.5) that allows authorization policy evasion when headers have multiple values; a critical JWKS resolver failure (CVSS 8.7) that

3m read timeFrom istio.io
Post cover image
Table of contents
CVEAm I Impacted?

Sort: