Cleartext transmission of sensitive information in Istio - #VU146863

 

Cleartext transmission of sensitive information in Istio - #VU146863

Published: September 3, 2026


Vulnerability identifier: #VU146863
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read or modify plaintext traffic.

The vulnerability exists due to improper security behavior in BackendTLSPolicy handling on sidecar proxies when a CA reference cannot be resolved. A remote user can position on the network path to observe or alter traffic to read or modify plaintext traffic.

Gateway proxies are not affected and fail closed. The downgrade is silent, and only ResolvedRefs=False on the policy indicates the condition.


Affected software

Istio

Remediation

Install security update from vendor's website.

Istio - addressed in versions 1.29.7, 1.30.4

External References

Related Security Bulletins