Istio 1.30.1 is a patch release addressing one high-severity CVE and multiple bug fixes. The security update (CVE-2026-47774, CVSS 7.5) fixes a denial-of-service vulnerability in Envoy where crafted HTTP/2 requests could exhaust memory via improper header size accounting. Bug fixes include: a new istioctl analyze check for outdated Gateway API CRDs, nftables JSON support detection with iptables fallback, BackendTLSPolicy conflict resolution, HTTPS listener TLS certificate delivery via ListenerSet, silent dropping of invalid HTTPRoute/GRPCRoute filters, multi-network ambient waypoint routing, consistentHash load balancing regression after scaling, a concurrent map writes panic in istio-cni, an ambient mode health policy contamination bug, agentgateway ListenerSet handling, and a multicluster ClusterStore deadlock fix.