CVE-2026-31837Patch(istio / istio)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch istio istio systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-1392

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • istio

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
istio

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-07-15: 1Patch / Workaround · 2026-03-10: 103-1003-1107-15
Signal classification3 categories
Patch
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-101
Patch1
2026-03-111
General1
2026-07-151
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-31837 Istio JWKS Resolver Vulnerability Exposing Hardcoded Authenticati... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31837 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet references CVE-2026-31837 and links to a vulnerability details page but offers no additional information on PoC, exploitation, patching, or technical details.

    0001037
    4.0K followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-31837](https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c) Istio is... https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c #Vulnerability #CVE #ZeroDay

    Post summary

    The tweet announces the discovery of CVE-2026-31837 in Istio, directing readers to a GitHub advisory for additional information.

    0000041
    11 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31837 Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes … https://www.cve.org/CVERecord?id=CVE-2026-31837

    Post summary

    The text notes that Istio versions 1.29.1, 1.28.5, and 1.27.8 contain a patch for CVE‑2026‑31837, fixing a vulnerability that affects earlier releases.

    0000090
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appistioistio---

Explore more