Improper access control in Istio - CVE-2026-31838
Published: April 20, 2026
Istio
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Envoy RBAC header matching when handling requests with multiple HTTP header values. A remote attacker can send a specially crafted request with multiple header values to disclose sensitive information.
This may allow unauthorized requests to reach protected services when authorization policies rely on such header-based matching conditions.