Istio is a narrowly focused service mesh platform that, despite a small product portfolio, sits at the network-control boundary of Kubernetes clusters and microservice architectures, making its vulnerabilities high-impact across cloud-native deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the trust and privilege required of mesh components that mediate authentication, authorization, and traffic control. The recurring exposure centers on authorization and authentication flaws, resource-exhaustion conditions, and pointer-safety issues that arise in the language runtime and request-routing layers of the mesh architecture. Defenders should prioritize Istio updates and treat control-plane access as a high-value attack surface, since a compromise of mesh policy or credential handling affects every workload in scope. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Istio over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2022-21679CRITICAL Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts might be accidentally bypassed f | Jan 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-31921CRITICAL Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorizat | Jun 2, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-31045CRITICAL Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memor | Jun 9, 2022 | 9.8 | 30 | NO | NO |
CVE-2026-41413HIGH Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is created with a jwksUri pointin | May 7, 2026 | 7.7 | 29 | NO | NO |
CVE-2026-31837HIGH Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or | Mar 10, 2026 | 7.5 | 28 | NO | NO |
CVE-2022-21701HIGH Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE` | Jan 19, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-34824HIGH Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can b | Jun 29, 2021 | 8.8 | 28 | NO | NO |
CVE-2019-14993HIGH Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, o | Aug 13, 2019 | 7.5 | 26 | NO | NO |
CVE-2022-39278HIGH Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the | Oct 13, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Istio.
Media articles that mention a CVE ID that affects a product developed by Istio — matched by CVE ID, not by vendor name.