Istio 1.29.4 is a patch release addressing one high-severity security vulnerability (CVE-2026-47774, CVSS 7.5) in Envoy that allows unauthenticated remote attackers to exhaust memory via crafted HTTP/2 requests. Bug fixes include: a startup check for nftables JSON support with automatic iptables fallback, TLS certificate delivery for HTTPS listeners in ListenerSet with manual Gateway deployments, silent dropping of invalid HTTPRoute/GRPCRoute header filters, multi-network ambient waypoint routing, a concurrent map writes panic in istio-cni, and an ambient mode bug where publishNotReadyAddresses combined with traffic distribution presets incorrectly propagated healthPolicy to unrelated services.
8.1K Impressions