CVE-2026-31837

Severity CVSS v4.0:
HIGH
Type:
CWE-200 Information Leak / Disclosure
Publication date:
10/03/2026
Last modified:
18/03/2026

Description

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:* 1.27.8 (excluding)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:* 1.28.0 (including) 1.28.5 (excluding)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:* 1.29.0 (including) 1.29.1 (excluding)