---
id: CVE-2026-31837
title: 'Istio is an open platform to connect, manage, and secure microservices'
summary: >-
  Istio is an open platform to connect, manage, and secure microservices. Prior
  to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS
  resolver becomes unavailable or the fetch fails, exposing hardcoded defaults
  regardless …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
  - CWE-1392
vendor: istio
product: istio
affected:
  - istio < 1.27.8
  - 'istio >= 1.28.0, < 1.28.5'
  - 'istio >= 1.29.0, < 1.29.1'
patched:
  - istio 1.29.1
published: '2026-03-10'
updated: '2026-07-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-31837'
references:
  - url: 'https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c'
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:10184'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:5948'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:5950'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:5952'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-31837'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2446344'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31837.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00676
epssPercentile: 0.50173
ingestedAt: '2026-07-16T02:48:54.737Z'
---

## Overview

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.

## Affected

- `istio < 1.27.8`
- `istio >= 1.28.0, < 1.28.5`
- `istio >= 1.29.0, < 1.29.1`

## Remediation

Upgrade past the affected range:

- `istio 1.29.1`
