Istio 1.28.9 is a patch release focused entirely on security fixes. It addresses 13 Envoy CVEs covering a range of vulnerabilities including: a denial-of-service via HTTP/3 QPACK blocked decoding (CVSS 7.5), a PROXY protocol header smuggling bug (CVSS 4.8), ext_proc filter issues (CVSS 6.5), use-after-free crashes in ext_authz and OAuth2 filters, a memory exhaustion flaw in the Zstd decompressor (CVSS 7.5), SAN validation bypass via NUL byte injection (CVSS 4.4), a gRPC stats filter crash (CVSS 6.5), HTTP/3 content-length validation issues (CVSS 7.5), a padding oracle in OAuth2 AES-256-CBC cookie decryption (CVSS 6.8), and a JSON nesting depth limit to prevent DoS (CVSS 7.5). Users running Istio 1.28.x are advised to upgrade.
Table of contents
Envoy CVEs7.5K Impressions