VDB
CVE-2026-31837
CVE-2026-31837
PUBLISHED
CVSS 8.699999809265137 HIGH
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.
EPSS 0.07% · 22.0th percentile
Risk Scores
CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.07%
22.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| istio | istio | >= 1.28.0-alpha.0, < 1.28.5, < 1.27.8, 0 |
Timeline
- Mar 10, 2026 CVE Published
- Mar 11, 2026 EPSS Score
- Mar 11, 2026 CVE Updated
- Mar 12, 2026 EPSS Score
- Mar 13, 2026 EPSS Score
- Mar 14, 2026 EPSS Score
- Mar 15, 2026 EPSS Score
- Mar 16, 2026 EPSS Score
- Mar 17, 2026 EPSS Score
- Mar 17, 2026 Coalition ESS Score
- Mar 18, 2026 EPSS Score
- Mar 19, 2026 EPSS Score