ISTIO-SECURITY-2026-004

CVE reported by Envoy.

Jun 4, 2026

Disclosure Details
CVE(s)CVE-2026-47774
CVSS Impact Score7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Releases1.30.0
1.29.0 to 1.29.3
1.28.0 to 1.28.7

CVE

Envoy CVEs

Am I Impacted?

You are impacted if you are running an affected version of Istio and accept downstream HTTP/2 traffic. This includes any Istio deployment that exposes services to external clients or untrusted workloads over HTTP/2 or gRPC, as an attacker can send specially crafted requests with large cookie headers to trigger excessive memory consumption.

Mitigation