Database/Container, Kubernetes & orchestration
Istio: A user with CREATE on Gateway API resources escalates privilege in istiod
CVSS 5.0CVE-2022-21701Container, Kubernetes & orchestrationcurated
Impact
A user with CREATE on Gateway API resources escalates privilege in istiod
Who can reach it
Cluster user with namespace access and Gateway API rights
What to do
Rolling istiod upgrade; restrict Gateway creation
References
Related entries
- Istio: A RequestAuthentication jwksUri pointed at an internal service makes istiod issue an unauthenticated requestCVE-2026-41413 · IstioMedium
- Istio: With AUTO_PASSTHROUGH gateways, an external client reaches arbitrary in-cluster services, bypassingCVE-2021-31921 · IstioCritical
- Istio: Gateway/DestinationRule credentialName can read TLS secrets from other namespacesCVE-2021-34824 · IstioHigh
- Istio: When JWKS resolution fails, istiod falls back to hardcoded defaults, weakening JWT validationCVE-2026-31837 · IstioHigh
- Istio: Case-sensitivity mismatch in host matching bypasses authorization policyCVE-2021-39155 · IstioHigh
- Istio: Host header with a port bypasses AuthorizationPolicy host matchingCVE-2021-39156 · IstioHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.