Where
-Infinity
0
EOL
Apr 16, 2025

End of life: 4/16/2025, Latest version: 1.23.6

First published (updated )
EOL
Apr 16, 2025

End of life: 4/16/2025, Latest version: 1.23.6

First published (updated )
EOL
Jan 22, 2025

End of life: 1/22/2025, Latest version: 1.22.8

First published (updated )
EOL
Jan 22, 2025

End of life: 1/22/2025, Latest version: 1.22.8

First published (updated )
EOL
Jun 25, 2024

End of life: 6/25/2024, Latest version: 1.20.8

First published (updated )
EOL
Jun 25, 2024

End of life: 6/25/2024, Latest version: 1.20.8

First published (updated )
EOL
Apr 24, 2024

End of life: 4/24/2024, Latest version: 1.19.10

First published (updated )
EOL
Apr 24, 2024

End of life: 4/24/2024, Latest version: 1.19.10

First published (updated )
EOL
Jan 4, 2024

End of life: 1/4/2024, Latest version: 1.18.7

First published (updated )
EOL
Jan 4, 2024

End of life: 1/4/2024, Latest version: 1.18.7

First published (updated )
EOL
Oct 27, 2023

End of life: 10/27/2023, Latest version: 1.17.8

First published (updated )
EOL
Oct 27, 2023

End of life: 10/27/2023, Latest version: 1.17.8

First published (updated )
EOL
Jul 25, 2023

End of life: 7/25/2023, Latest version: 1.16.7

First published (updated )
EOL
Jul 25, 2023

End of life: 7/25/2023, Latest version: 1.16.7

First published (updated )
Severity
7.6
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Version 1.15.3 contains a patch for this issue. There are no known workarounds.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An uncontrolled resource consumption flaw was found in the Istio control plane, istiod. This issue could allow an unauthenticated remote attacker to send a specially crafted or oversized message that could cause a denial of service.

1 / 3
First published (updated )
EOL
Apr 4, 2023

End of life: 4/4/2023, Latest version: 1.15.7

First published (updated )
EOL
Apr 4, 2023

End of life: 4/4/2023, Latest version: 1.15.7

First published (updated )
EOL
Dec 27, 2022

End of life: 12/27/2022, Latest version: 1.14.6

First published (updated )
EOL
Dec 27, 2022

End of life: 12/27/2022, Latest version: 1.14.6

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A flaw was found in Istio. Memory access violation of ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access, resulting in undefined behavior or crashing.

1 / 3
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A stack exhaustion flaw was found in the Istio control plane. This flaw allows a remote unauthenticated attacker to send a specially crafted or oversized message to crash the control plane process, resulting in a denial of service condition.

1 / 3
First published (updated )
EOL
Oct 12, 2022

End of life: 10/12/2022, Latest version: 1.13.9

First published (updated )
EOL
Oct 12, 2022

End of life: 10/12/2022, Latest version: 1.13.9

First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have CREATE permission for gateways.gateway.networking.k8s.io objects can escalate this privilege to create other resources that they may not have access to, such as Pod. This vulnerability impacts only an Alpha level feature, the Kubernetes Gateway API. This is not the same as the Istio Gateway type (gateways.networking.istio.io), which is not vulnerable. Users are advised to upgrade to resolve this issue. Users unable to upgrade should implement any of the following which will prevent this vulnerability: Remove the gateways.gateway.networking.k8s.io CustomResourceDefinition, set PILOTENABLEGATEWAYAPIDEPLOYMENTCONTROLLER=true environment variable in Istiod, or remove CREATE permissions for gateways.gateway.networking.k8s.io objects from untrusted users.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts might be accidentally bypassed for ALLOW action or rejected unexpectedly for DENY action during the upgrade from 1.11 to 1.12.0/1.12.1. Istio 1.12 supports the hosts and notHosts fields in authorization policy with a new Envoy API shipped with the 1.12 data plane. A bug in the 1.12.0 and 1.12.1 incorrectly uses the new Envoy API with the 1.11 data plane. This will cause the hosts and notHosts fields to be always matched regardless of the actual value of the host header when mixing 1.12.0/1.12.1 control plane and 1.11 data plane. Users are advised to upgrade or to not mix the 1.12.0/1.12.1 control plane with 1.11 data plane if using hosts or notHosts field in authorization policy.

First published (updated )
EOL
Jul 12, 2022

End of life: 7/12/2022, Latest version: 1.12.9

First published (updated )
EOL
Jul 12, 2022

End of life: 7/12/2022, Latest version: 1.12.9

First published (updated )
EOL
Mar 25, 2022

End of life: 3/25/2022, Latest version: 1.11.8

First published (updated )
EOL
Mar 25, 2022

End of life: 3/25/2022, Latest version: 1.11.8

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203