Istio 1.28.8 is a patch release addressing one high-severity security vulnerability and three bug fixes. The security update patches CVE-2026-47774 (CVSS 7.5), a denial-of-service vulnerability in Envoy where crafted HTTP/2 requests can exhaust memory due to improper cookie header accounting and HPACK decoding limits. Bug fixes include: TLS certificate delivery failures for HTTPS listeners using ListenerSet with manual Gateway deployment, silent dropping of HTTPRoute/GRPCRoute filters with invalid header values instead of reporting errors, and an ambient mode bug where a Service with publishNotReadyAddresses and zone/node traffic distribution preferences incorrectly propagated healthPolicy:AllowAll to unrelated Services, causing traffic to be routed to not-ready endpoints cluster-wide.