Database/Container, Kubernetes & orchestration
Istio: When JWKS resolution fails, istiod falls back to hardcoded defaults, weakening JWT validation
CVSS 8.7CVE-2026-31837Container, Kubernetes & orchestrationcurated
Impact
When JWKS resolution fails, istiod falls back to hardcoded defaults, weakening JWT validation
Who can reach it
Unauthenticated network, exploitable by first disrupting JWKS reachability
What to do
Rolling istiod upgrade to 1.29.1/1.28.5/1.27.8+
References
Related entries
- Istio: Case-sensitivity mismatch in host matching bypasses authorization policyCVE-2021-39155 · IstioHigh
- Istio: Host header with a port bypasses AuthorizationPolicy host matchingCVE-2021-39156 · IstioHigh
- Istio: Localhost access to the istiod pod lets a user impersonate any workload identity in the meshCVE-2022-39388 · IstioHigh
- Istio: Crafted message crashes istiodCVE-2022-23635 · IstioHigh
- Istio: Crafted message DoSes istiodCVE-2022-39278 · IstioHigh
- Istio: Authentication Policy exact-path matching allows unauthorized access to HTTP pathsCVE-2020-8595 · IstioHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.