Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-31837

Опубликовано: 10 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Версия до 1.27.8 (исключая)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Версия от 1.28.0 (включая) до 1.28.5 (исключая)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Версия от 1.29.0 (включая) до 1.29.1 (исключая)

EPSS

Процентиль: 30%
0.00378
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-1392

Связанные уязвимости

CVSS3: 7.5
redhat
5 месяцев назад

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.

EPSS

Процентиль: 30%
0.00378
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-1392