Protection Mechanism Failure in Istio - CVE-2026-31837
Published: April 20, 2026
Istio
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of jwks resolver failures in jwks resolver handling when the jwks resolver becomes unavailable or a fetch fails. A remote attacker can trigger jwks resolver failure conditions to disclose sensitive information.
Hardcoded default keys may be exposed regardless of use of the RequestAuthentication resource.