istio has 4 CVEs on record between 2021 and 2026. The median CVSS is 7.8 (high). Most affected products: istio (2), istio.io/istio (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- istio 2
- istio.io/istio 2
Worst active — by depth score
CVE-2021-39156High· 8.1Istio Fragments in Path May Lead to Authorization Policy Bypass57CVE-2021-39155High· 8.3Authorization Policy Bypass Due to Case Insensitive Host Comparison46CVE-2022-23635High· 7.5Istio is an open platform to connect, manage, and secure microservices42CVE-2026-31837High· 7.5Istio is an open platform to connect, manage, and secure microservices41
istio vulnerabilities
CVEs affecting istio, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-31837High· 7.5Istio is an open platform to connect, manage, and secure microservices
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless …
CVE-2022-23635High· 7.5Istio is an open platform to connect, manage, and secure microservices
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted mes…
CVE-2021-39156High· 8.1PoCIstio Fragments in Path May Lead to Authorization Policy Bypass
Istio Fragments in Path May Lead to Authorization Policy Bypass
CVE-2021-39155High· 8.3Authorization Policy Bypass Due to Case Insensitive Host Comparison
Authorization Policy Bypass Due to Case Insensitive Host Comparison