Protection Mechanism Failure in Istio - CVE-2026-31837

 

Protection Mechanism Failure in Istio - CVE-2026-31837

Published: April 20, 2026


Vulnerability identifier: #VU126607
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31837
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper handling of jwks resolver failures in jwks resolver handling when the jwks resolver becomes unavailable or a fetch fails. A remote attacker can trigger jwks resolver failure conditions to disclose sensitive information.

Hardcoded default keys may be exposed regardless of use of the RequestAuthentication resource.


Affected software

Istio

How to mitigate CVE-2026-31837

Install security update from vendor's website.

Istio - addressed in versions 1.27.8, 1.28.5, 1.29.1

External References

Related Security Bulletins