CVE-2021-39156High· 8.1▾ MidnightPoC availableIstio Fragments in Path May Lead to Authorization Policy Bypass
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.1%
1.1% → 1.2%
1 GitHub repo
Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exploitable vulnerability where an HTTP request with #fragment in the path may bypass Istio’s URI path based authorization policies.
A Lua filter may be written to normalize the path. This is similar to the Path normalization presented in the Security Best Practices guide.
More details can be found in the Istio Security Bulletin
If you have any questions or comments about this advisory, please email us at [email protected]
istio.io/istio < 1.9.8istio.io/istio >= 1.10.0, < 1.10.4istio.io/istio >= 1.11.0, < 1.11.1Upgrade to a patched release:
istio.io/istio 1.9.8istio.io/istio 1.10.4istio.io/istio 1.11.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-39155High· 8.3Authorization Policy Bypass Due to Case Insensitive Host Comparison
CVE-2022-23635High· 7.5Istio is an open platform to connect, manage, and secure microservices
CVE-2026-31837High· 7.5Istio is an open platform to connect, manage, and secure microservices