Database/Container, Kubernetes & orchestration
Istio: Multiple or escaped slashes bypass an Istio authorization policy
CVSS 6.5CVE-2021-31920Container, Kubernetes & orchestrationcurated
Impact
Multiple or escaped slashes bypass an Istio authorization policy
Who can reach it
Unauthenticated network
What to do
Rolling istiod upgrade plus sidecar restart
References
Related entries
- Istio: serviceAccounts and notServiceAccounts in AuthorizationPolicy are evaluated incorrectlyCVE-2026-39350 · IstioMedium
- Istio: A user with CREATE on Gateway API resources escalates privilege in istiodCVE-2022-21701 · IstioMedium
- Istio: A RequestAuthentication jwksUri pointed at an internal service makes istiod issue an unauthenticated requestCVE-2026-41413 · IstioMedium
- Istio: With AUTO_PASSTHROUGH gateways, an external client reaches arbitrary in-cluster services, bypassingCVE-2021-31921 · IstioCritical
- Istio: Gateway/DestinationRule credentialName can read TLS secrets from other namespacesCVE-2021-34824 · IstioHigh
- Istio: When JWKS resolution fails, istiod falls back to hardcoded defaults, weakening JWT validationCVE-2026-31837 · IstioHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.