JWKS Resolver Vulnerability in Istio by Istio
CVE-2026-31837
8.7HIGH
What is CVE-2026-31837?
Istio, a platform for managing and securing microservices, presents a security concern when the JWKS resolver is unavailable or fails. In versions prior to 1.29.1, 1.28.5, and 1.27.8, this issue exposes hardcoded defaults despite the presence of the RequestAuthentication resource, potentially leading to unauthorized access and compromised security protocols.
Affected Version(s)
istio >= 1.29.0-alpha.0, < 1.29.1 < 1.29.0-alpha.0, 1.29.1
istio >= 1.28.0-alpha.0, < 1.28.5 < 1.28.0-alpha.0, 1.28.5
istio < 1.27.8 < 1.27.8
