istio vulnerabilities
CVEs whose affected-version data names the istio package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-31837High· 7.5Istio is an open platform to connect, manage, and secure microservices
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless …
▾ Twilightistio · istioEPSS 0.38%via NVD
CVE-2022-23635High· 7.5Istio is an open platform to connect, manage, and secure microservices
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted mes…
▾ Twilightistio · istioEPSS 1.7%via NVD