CVE-2026-31837

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*

History

30 Jun 2026, 03:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:10184 -
  • () https://access.redhat.com/errata/RHSA-2026:5948 -
  • () https://access.redhat.com/errata/RHSA-2026:5950 -
  • () https://access.redhat.com/errata/RHSA-2026:5952 -
  • () https://access.redhat.com/security/cve/CVE-2026-31837 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2446344 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31837.json -
CWE CWE-1392

18 Mar 2026, 18:59

Type Values Removed Values Added
CPE cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
References () https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c - () https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c - Vendor Advisory
First Time Istio istio
Istio
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

11 Mar 2026, 13:52

Type Values Removed Values Added
Summary
  • (es) Istio es una plataforma abierta para conectar, gestionar y proteger microservicios. Antes de 1.29.1, 1.28.5 y 1.27.8, un usuario de Istio se ve afectado si el resolvedor JWKS deja de estar disponible o la obtención falla, exponiendo valores predeterminados codificados independientemente del uso del recurso RequestAuthentication. Esta vulnerabilidad está corregida en 1.29.1, 1.28.5 y 1.27.8.

10 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 22:16

Updated : 2026-07-20 12:18


NVD link : CVE-2026-31837

Mitre link : CVE-2026-31837

CVE.ORG link : CVE-2026-31837


JSON object : View

Products Affected

istio

  • istio
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-1392

Use of Default Credentials