Istio
Read post

Istio / ISTIO-SECURITY-2026-005

Istio security advisory ISTIO-SECURITY-2026-005 discloses multiple CVEs affecting Envoy and Istio, with patches available in versions 1.29.5 and 1.28.9. Envoy fixes include a denial-of-service via HTTP/3 QPACK blocked decoding (CVSS 7.5), a PROXY protocol header smuggling bug (CVSS 4.8), a use-after-free in the ext_authz filter (CVSS 5.9), a memory exhaustion in the Zstd decompressor (CVSS 7.5), a padding oracle in the OAuth2 filter's AES-256-CBC cookie decryption (CVSS 6.8), SAN validation bypass via embedded NUL bytes (CVSS 4.4), and several crash/use-after-free bugs across HTTP/3, ext_proc, gRPC stats, and DNS query handling.

    #security#istio#service-mesh#envoy
Jun 24•3m read time•From istio.io
Post cover image
Table of contents
Envoy CVEs
423 Impressions
Istio's image
Istio

Istio is an open-source service mesh platform that helps developers connect, secure, and manage micr...

50 Followers

•

229 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard