Description
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain multiple values. An attacker could craft requests with multiple header values in a way that causes Envoy to evaluate the header differently than intended, potentially bypassing authorization checks. This may allow unauthorized requests to reach protected services when policies depend on such header-based matching conditions. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/istio/istio/security/advisories/GHSA-974c-2wxh-g4ww
X_Refsource_Misc x_refsource_misc
https://github.com/istio/istio/commit/004fd6921314a8e2293fd195d91645dcbbff0aa1
Scores
CVSS v3
5.3
EPSS
0.0021
EPSS Percentile
11.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (3)
istio/istio
< 1.27.8 (2 CPE variants)
istio/istio
>= 1.28.0-alpha.0, < 1.28.5
istio/istio
>= 1.29.0-alpha.0, < 1.29.1
Published
Mar 10, 2026
Tracked Since
Mar 11, 2026