Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-31838

Опубликовано: 10 мар. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain multiple values. An attacker could craft requests with multiple header values in a way that causes Envoy to evaluate the header differently than intended, potentially bypassing authorization checks. This may allow unauthorized requests to reach protected services when policies depend on such header-based matching conditions. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Версия до 1.27.8 (исключая)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Версия от 1.28.0 (включая) до 1.28.5 (исключая)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Версия от 1.29.0 (включая) до 1.29.1 (исключая)

EPSS

Процентиль: 12%
0.00214
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.3
redhat
5 месяцев назад

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain multiple values. An attacker could craft requests with multiple header values in a way that causes Envoy to evaluate the header differently than intended, potentially bypassing authorization checks. This may allow unauthorized requests to reach protected services when policies depend on such header-based matching conditions. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.

EPSS

Процентиль: 12%
0.00214
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-863