Istio 1.29.4 is a patch release addressing one high-severity security vulnerability (CVE-2026-47774, CVSS 7.5) in Envoy that allows unauthenticated remote attackers to exhaust memory via crafted HTTP/2 requests. Bug fixes include: a startup check for nftables JSON support with automatic iptables fallback, TLS certificate delivery for HTTPS listeners in ListenerSet with manual Gateway deployments, silent dropping of invalid HTTPRoute/GRPCRoute header filters, multi-network ambient waypoint routing, a concurrent map writes panic in istio-cni, and an ambient mode bug where publishNotReadyAddresses combined with traffic distribution presets incorrectly propagated healthPolicy to unrelated services.

2m read timeFrom istio.io
Post cover image
Table of contents
Security UpdateChanges
8.1K Impressions