Istio security advisory ISTIO-SECURITY-2026-005 discloses multiple CVEs affecting Envoy and Istio, with patches available in versions 1.29.5 and 1.28.9. Envoy fixes include a denial-of-service via HTTP/3 QPACK blocked decoding (CVSS 7.5), a PROXY protocol header smuggling bug (CVSS 4.8), a use-after-free in the ext_authz filter (CVSS 5.9), a memory exhaustion in the Zstd decompressor (CVSS 7.5), a padding oracle in the OAuth2 filter's AES-256-CBC cookie decryption (CVSS 6.8), SAN validation bypass via embedded NUL bytes (CVSS 4.4), and several crash/use-after-free bugs across HTTP/3, ext_proc, gRPC stats, and DNS query handling.
Table of contents
Envoy CVEs423 Impressions