Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Istio

First CVE: Jun 5, 2019Active for: 7 yearsTotal CVEs: 28
71.5
VTI Score
TOP TARGET

Istio is a narrowly focused service mesh platform that, despite a small product portfolio, sits at the network-control boundary of Kubernetes clusters and microservice architectures, making its vulnerabilities high-impact across cloud-native deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the trust and privilege required of mesh components that mediate authentication, authorization, and traffic control. The recurring exposure centers on authorization and authentication flaws, resource-exhaustion conditions, and pointer-safety issues that arise in the language runtime and request-routing layers of the mesh architecture. Defenders should prioritize Istio updates and treat control-plane access as a high-value attack surface, since a compromise of mesh policy or credential handling affects every workload in scope. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
4.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
3.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Istio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2019
7 years ago
Most Recent CVE
May 7, 2026
78 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2022-21679CRITICAL
Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts might be accidentally bypassed f
Jan 19, 20229.831NONO
CVE-2021-31921CRITICAL
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorizat
Jun 2, 20219.831NONO
CVE-2022-31045CRITICAL
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memor
Jun 9, 20229.830NONO
CVE-2026-41413HIGH
Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is created with a jwksUri pointin
May 7, 20267.729NONO
CVE-2026-31837HIGH
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or
Mar 10, 20267.528NONO
CVE-2022-21701HIGH
Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE`
Jan 19, 20228.828NONO
CVE-2021-34824HIGH
Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can b
Jun 29, 20218.828NONO
CVE-2019-14993HIGH
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, o
Aug 13, 20197.526NONO
CVE-2022-39278HIGH
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the
Oct 13, 20227.525NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
18%
64%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (7.1%)
Attack Complexity
Low24 (85.7%)
High4 (14.3%)
Unknown0 (0.0%)
User Interaction
None27 (96.4%)
Unknown0 (0.0%)
Required1 (3.6%)
Privileges Required
Low8 (28.6%)
High0 (0.0%)
None20 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
1 CVE
3.6% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.6% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Istio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Istio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Istio's Products

View all 3 CNAs →

Top CWEs