Database/Container, Kubernetes & orchestration
Istio: Case-sensitivity mismatch in host matching bypasses authorization policy
CVSS 8.3CVE-2021-39155Container, Kubernetes & orchestrationcurated
Impact
Case-sensitivity mismatch in host matching bypasses authorization policy
Who can reach it
Unauthenticated network
What to do
Rolling istiod upgrade
References
Related entries
- Istio: Host header with a port bypasses AuthorizationPolicy host matchingCVE-2021-39156 · IstioHigh
- Istio: Localhost access to the istiod pod lets a user impersonate any workload identity in the meshCVE-2022-39388 · IstioHigh
- Istio: Crafted message crashes istiodCVE-2022-23635 · IstioHigh
- Istio: Crafted message DoSes istiodCVE-2022-39278 · IstioHigh
- Istio: Authentication Policy exact-path matching allows unauthorized access to HTTP pathsCVE-2020-8595 · IstioHigh
- Istio: Envoy RBAC header matching flaw bypasses header-based authorization policyCVE-2026-31838 · IstioMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.