Istio 1.28.9 is a patch release focused entirely on security fixes. It addresses 13 Envoy CVEs covering a range of vulnerabilities including: a denial-of-service via HTTP/3 QPACK blocked decoding (CVSS 7.5), a PROXY protocol header smuggling bug (CVSS 4.8), ext_proc filter issues (CVSS 6.5), use-after-free crashes in ext_authz and OAuth2 filters, a memory exhaustion flaw in the Zstd decompressor (CVSS 7.5), SAN validation bypass via NUL byte injection (CVSS 4.4), a gRPC stats filter crash (CVSS 6.5), HTTP/3 content-length validation issues (CVSS 7.5), a padding oracle in OAuth2 AES-256-CBC cookie decryption (CVSS 6.8), and a JSON nesting depth limit to prevent DoS (CVSS 7.5). Users running Istio 1.28.x are advised to upgrade.

3m read timeFrom istio.io
Post cover image
Table of contents
Envoy CVEs
7.5K Impressions