News
Select security bulletins, release announcements, or support announcements to stay up to date.
May 17, 2022
Announcing Istio 1.13.4
Istio 1.13.4 patch release.
May 6, 2022
Announcing Istio 1.12.7
Istio 1.12.7 patch release.
Apr 18, 2022
Announcing Istio 1.13.3
Istio 1.13.3 patch release.
Apr 6, 2022
Announcing Istio 1.12.6
Istio 1.12.6 patch release.
Mar 25, 2022
Support for Istio 1.11 has ended
Istio 1.11 end of life announcement.
Mar 16, 2022
Support for Istio 1.11 ends on March 25th, 2022
Upcoming Istio 1.11 end of life announcement.
Mar 9, 2022
ISTIO-SECURITY-2022-004
Unauthenticated control plane denial of service attack due to stack exhaustion.
Mar 9, 2022
Announcing Istio 1.13.2
Istio 1.13.2 patch release.
Mar 9, 2022
Announcing Istio 1.12.5
Istio 1.12.5 patch release.
Mar 9, 2022
Announcing Istio 1.11.8
Istio 1.11.8 patch release.
Feb 22, 2022
ISTIO-SECURITY-2022-003
Multiple CVEs related to istiod Denial of Service and Envoy.
Feb 22, 2022
Announcing Istio 1.13.1
Istio 1.13.1 patch release.
Feb 22, 2022
Announcing Istio 1.12.4
Istio 1.12.4 patch release.
Feb 22, 2022
Announcing Istio 1.11.7
Istio 1.11.7 patch release.
Feb 11, 2022
Announcing Istio 1.13
Istio 1.13 release announcement.
Feb 11, 2022
Istio 1.13 Upgrade Notes
Important changes to consider when upgrading to Istio 1.13.0.
Feb 11, 2022
Istio 1.13 Change Notes
Istio 1.13.0 change notes.
Feb 10, 2022
Announcing Istio 1.12.3
Istio 1.12.3 patch release.
Feb 3, 2022
Announcing Istio 1.11.6
Istio 1.11.6 patch release.
Jan 18, 2022
ISTIO-SECURITY-2022-002
Privileged Escalation in Kubernetes Gateway API.
Jan 18, 2022
ISTIO-SECURITY-2022-001
Authorization Policy For Host Rules During Upgrades.
Jan 18, 2022
Announcing Istio 1.12.2
Istio 1.12.2 patch release.
Jan 7, 2022
Support for Istio 1.10 has ended
Istio 1.10 end of life announcement.
Dec 7, 2021
Announcing Istio 1.12.1
Istio 1.12.1 patch release.
Dec 2, 2021
Announcing Istio 1.11.5
Istio 1.11.5 patch release.
Nov 29, 2021
Announcing Istio 1.10.6
Istio 1.10.6 patch release.
Nov 19, 2021
Support for Istio 1.10 ends on December 30th, 2021
Upcoming Istio 1.10 end of life announcement.
Nov 18, 2021
Announcing Istio 1.12
Istio 1.12 release announcement.
Nov 18, 2021
Istio 1.12 Upgrade Notes
Important changes to consider when upgrading to Istio 1.12.0.
Nov 18, 2021
Istio 1.12 Change Notes
Istio 1.12.0 change notes.
Oct 14, 2021
Announcing Istio 1.11.4
Istio 1.11.4 patch release.
Oct 8, 2021
Support for Istio 1.9 has ended
Istio 1.9 end of life announcement.
Oct 8, 2021
Announcing Istio 1.9.9
Istio 1.9.9 patch release.
Oct 7, 2021
Announcing Istio 1.10.5
Istio 1.10.5 patch release.
Sep 23, 2021
Announcing Istio 1.11.3
Istio 1.11.3 patch release.
Sep 3, 2021
Revised - Support for Istio 1.9 ends on October 5th, 2021
Revised Istio 1.9 end of life announcement.
Sep 2, 2021
Announcing Istio 1.11.2
Istio 1.11.2 patch release.
Aug 24, 2021
ISTIO-SECURITY-2021-008
Multiple CVEs related to AuthorizationPolicy, EnvoyFilter and Envoy.
Aug 24, 2021
Announcing Istio 1.9.8
Istio 1.9.8 patch release.
Aug 24, 2021
Announcing Istio 1.11.1
Istio 1.11.1 patch release.
Aug 24, 2021
Announcing Istio 1.10.4
Istio 1.10.4 patch release.
Aug 12, 2021
Announcing Istio 1.11
Istio 1.11 release announcement.
Aug 12, 2021
Istio 1.11 Upgrade Notes
Important changes to consider when upgrading to Istio 1.11.0.
Aug 12, 2021
Istio 1.11 Change Notes
Istio 1.11.0 release notes.
Jul 22, 2021
Announcing Istio 1.9.7
Istio 1.9.7 patch release.
Jul 21, 2021
Support for Istio 1.9 ends on August 24th, 2021
Upcoming Istio 1.9 end of life announcement.
Jul 16, 2021
Announcing Istio 1.10.3
Istio 1.10.3 patch release.
Jun 24, 2021
ISTIO-SECURITY-2021-007
Istio contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.
Jun 24, 2021
Announcing Istio 1.9.6
Istio 1.9.6 patch release.
Jun 24, 2021
Announcing Istio 1.10.2
Istio 1.10.2 patch release.
Jun 9, 2021
Announcing Istio 1.10.1
Istio 1.10.1 patch release.
May 18, 2021
Announcing Istio 1.10
Istio 1.10 release announcement.
May 18, 2021
Istio 1.10 Upgrade Notes
Important changes to consider when upgrading to Istio 1.10.0.
May 18, 2021
Istio 1.10 Change Notes
Istio 1.10.0 release notes.
May 12, 2021
Support for Istio 1.8 has ended
Istio 1.8 end of life announcement.
May 11, 2021
ISTIO-SECURITY-2021-006
An external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing configuration.
May 11, 2021
ISTIO-SECURITY-2021-005
HTTP request paths with multiple slashes or escaped slash characters may bypass path based authorization rules.
May 11, 2021
Announcing Istio 1.9.5
Istio 1.9.5 patch release.
May 11, 2021
Announcing Istio 1.8.6
Istio 1.8.6 patch release.
Apr 27, 2021
Announcing Istio 1.9.4
Istio 1.9.4 patch release.
Apr 15, 2021
ISTIO-SECURITY-2021-004
Potential misuse of mTLS-only fields in AuthorizationPolicy with plain text traffic.
Apr 15, 2021
ISTIO-SECURITY-2021-003
Apr 15, 2021
Announcing Istio 1.9.3
Istio 1.9.3 patch release.
Apr 15, 2021
Announcing Istio 1.8.5
Istio 1.8.5 patch release.
Apr 12, 2021
Support for Istio 1.8 ends on May 12th, 2021
Upcoming Istio 1.8 end of life announcement.
Apr 7, 2021
ISTIO-SECURITY-2021-002
Upgrades from older Istio versions can affect access control to an ingress gateway due to a change of container ports.
Mar 25, 2021
Announcing Istio 1.9.2
Istio 1.9.2 patch release.
Mar 10, 2021
Announcing Istio 1.8.4
Istio 1.8.4 patch release.
Mar 1, 2021
ISTIO-SECURITY-2021-001
JWT authentication can be bypassed when AuthorizationPolicy is misused.
Mar 1, 2021
Announcing Istio 1.9.1
Istio 1.9.1 patch release.
Feb 25, 2021
Support for Istio 1.7 has ended
Istio 1.7 end of life announcement.
Feb 25, 2021
Announcing Istio 1.7.8
Istio 1.7.8 patch release.
Feb 9, 2021
Announcing Istio 1.9
Istio 1.9 release announcement.
Feb 9, 2021
Istio 1.9 Upgrade Notes
Important changes to consider when upgrading to Istio 1.9.0.
Feb 9, 2021
Istio 1.9 Change Notes
Istio 1.9.0 release notes.
Feb 8, 2021
Announcing Istio 1.8.3
Istio 1.8.3 patch release.
Jan 29, 2021
Announcing Istio 1.7.7
Istio 1.7.7 patch release.
Jan 19, 2021
Support for Istio 1.7 ends on February 19th, 2021
Upcoming Istio 1.7 end of life announcement.
Jan 14, 2021
Announcing Istio 1.8.2
Istio 1.8.2 patch release.
Dec 10, 2020
Announcing Istio 1.7.6
Istio 1.7.6 patch release.
Dec 8, 2020
Announcing Istio 1.8.1
Istio 1.8.1 patch release.
Nov 23, 2020
Support for Istio 1.6 has ended
Istio 1.6 end of life announcement.
Nov 23, 2020
Announcing Istio 1.6.14
Istio 1.6.14 patch release.
Nov 21, 2020
ISTIO-SECURITY-2020-011
Envoy incorrectly restores the proxy protocol downstream address for non-HTTP connections.
Nov 19, 2020
Announcing Istio 1.8
Istio 1.8 release announcement.
Nov 19, 2020
Announcing Istio 1.7.5
Istio 1.7.5 patch release.
Nov 19, 2020
Istio 1.8 Upgrade Notes
Important changes to consider when upgrading to Istio 1.8.
Nov 19, 2020
Istio 1.8 Change Notes
Istio 1.8 release notes.
Oct 27, 2020
Announcing Istio 1.7.4
Istio 1.7.4 patch release.
Oct 27, 2020
Announcing Istio 1.6.13
Istio 1.6.13 patch release.
Oct 20, 2020
Support for Istio 1.6 ends on November 21st, 2020
Upcoming Istio 1.6 end of life announcement.
Oct 6, 2020
Announcing Istio 1.6.12
Istio 1.6.12 patch release.
Sep 29, 2020
ISTIO-SECURITY-2020-010
Sep 29, 2020
Announcing Istio 1.7.3
Istio 1.7.3 security release.
Sep 29, 2020
Announcing Istio 1.6.11
Istio 1.6.11 security release.
Sep 22, 2020
Announcing Istio 1.6.10
Istio 1.6.10 patch release.
Sep 18, 2020
Announcing Istio 1.7.2
Istio 1.7.2 patch release.
Sep 10, 2020
Announcing Istio 1.7.1
Istio 1.7.1 patch release.
Sep 9, 2020
Announcing Istio 1.6.9
Istio 1.6.9 patch release.
Aug 24, 2020
Support for Istio 1.5 has ended
Istio 1.5 end of life announcement.
Aug 24, 2020
Announcing Istio 1.5.10
Istio 1.5.10 patch release.
Aug 21, 2020
Announcing Istio 1.7
Istio 1.7 release announcement.
Aug 21, 2020
Istio 1.7 Upgrade Notes
Important changes to consider when upgrading to Istio 1.7.
Aug 21, 2020
Istio 1.7 Change Notes
Istio 1.7 release notes.
Aug 11, 2020
ISTIO-SECURITY-2020-009
Incorrect Envoy configuration for wildcard suffixes used for Principals/Namespaces in Authorization Policies for TCP Services.
Aug 11, 2020
Announcing Istio 1.6.8
Istio 1.6.8 patch release.
Aug 11, 2020
Announcing Istio 1.5.9
Istio 1.5.9 security release.
Jul 30, 2020
Announcing Istio 1.6.7
Istio 1.6.7 patch release.
Jul 29, 2020
Announcing Istio 1.6.6
Istio 1.6.6 patch release.
Jul 22, 2020
Support for Istio 1.5 ends on August 21st, 2020
Upcoming Istio 1.5 end of life announcement.
Jul 9, 2020
ISTIO-SECURITY-2020-008
Incorrect validation of wildcard DNS Subject Alternative Names.
Jul 9, 2020
Announcing Istio 1.6.5
Istio 1.6.5 patch release.
Jul 9, 2020
Announcing Istio 1.5.8
Istio 1.5.8 security release.
Jun 30, 2020
ISTIO-SECURITY-2020-007
Multiple denial of service vulnerabilities in Envoy.
Jun 30, 2020
Announcing Istio 1.6.4
Istio 1.6.4 security release.
Jun 30, 2020
Announcing Istio 1.5.7
Istio 1.5.7 security release.
Jun 22, 2020
Announcing Istio 1.4.10
Istio 1.4.10 security release.
Jun 18, 2020
Announcing Istio 1.6.3
Istio 1.6.3 patch release.
Jun 17, 2020
Announcing Istio 1.5.6
Istio 1.5.6 patch release.
Jun 11, 2020
ISTIO-SECURITY-2020-006
Denial of service in the HTTP2 library used by Envoy.
Jun 11, 2020
Announcing Istio 1.6.2
Istio 1.6.2 security release.
Jun 11, 2020
Announcing Istio 1.5.5
Istio 1.5.5 security release.
Jun 5, 2020
Support for Istio 1.4 has ended
Istio 1.4 end of life announcement.
Jun 4, 2020
Announcing Istio 1.6.1
Istio 1.6.1 patch release.
May 21, 2020
Announcing Istio 1.6
Istio 1.6 release announcement.
May 21, 2020
Istio 1.6 Upgrade Notes
Important changes to consider when upgrading to Istio 1.6.
May 21, 2020
Istio 1.6 Change Notes
Istio 1.6 release notes.
May 13, 2020
Announcing Istio 1.5.4
Istio 1.5.4 security release.
May 12, 2020
ISTIO-SECURITY-2020-005
Denial of service affecting telemetry v2.
May 12, 2020
Announcing Istio 1.5.3
Istio 1.5.3 security release.
May 12, 2020
Announcing Istio 1.4.9
Istio 1.4.9 patch release.
May 5, 2020
Support for Istio 1.4 ends on June 5th, 2020
Upcoming Istio 1.4 end of life announcement.
Apr 24, 2020
Announcing Istio 1.5.2
Istio 1.5.2 patch release.
Apr 23, 2020
Announcing Istio 1.4.8
Istio 1.4.8 patch release.
Mar 25, 2020
ISTIO-SECURITY-2020-004
Default Kiali security configuration allows full control of mesh.
Mar 25, 2020
Announcing Istio 1.5.1
Istio 1.5.1 patch release.
Mar 25, 2020
Announcing Istio 1.4.7
Istio 1.4.7 patch release.
Mar 5, 2020
Announcing Istio 1.5
Istio 1.5 release announcement.
Mar 5, 2020
Istio 1.5 Upgrade Notes
Important changes to consider when upgrading to Istio 1.5.
Mar 5, 2020
Isito 1.5 Change Notes
Istio 1.5 release notes.
Mar 3, 2020
ISTIO-SECURITY-2020-003
Two uncontrolled resource consumption and two incorrect access control vulnerabilities in Envoy.
Mar 3, 2020
Announcing Istio 1.4.6
Istio 1.4.6 patch release.
Feb 18, 2020
Announcing Istio 1.4.5
Istio 1.4.5 patch release.
Feb 14, 2020
Support for Istio 1.3 has ended
Istio 1.3 end of life announcement.
Feb 11, 2020
ISTIO-SECURITY-2020-002
Mixer policy check bypass caused by improperly accepting certain request headers.
Feb 11, 2020
ISTIO-SECURITY-2020-001
Authentication Policy bypass.
Feb 11, 2020
Announcing Istio 1.4.4
Istio 1.4.4 patch release.
Feb 11, 2020
Announcing Istio 1.3.8
Istio 1.3.8 patch release.
Feb 4, 2020
Announcing Istio 1.3.7
Istio 1.3.7 patch release.
Jan 15, 2020
Support for Istio 1.3 ends on February 14th, 2020
Upcoming Istio 1.3 end of life announcement.
Jan 8, 2020
Announcing Istio 1.4.3
Istio 1.4.3 patch release.
Dec 13, 2019
Support for Istio 1.2 has ended
Istio 1.2 end of life announcement.
Dec 10, 2019
ISTIO-SECURITY-2019-007
Heap overflow and improper input validation in Envoy.
Dec 10, 2019
Announcing Istio 1.4.2
Istio 1.4.2 patch release.
Dec 10, 2019
Announcing Istio 1.3.6
Istio 1.3.6 patch release.
Dec 10, 2019
Announcing Istio 1.2.10
Istio 1.2.10 patch release.
Dec 5, 2019
Announcing Istio 1.4.1
Istio 1.4.1 patch release.
Nov 14, 2019
Announcing Istio 1.4
Istio 1.4 release announcement.
Nov 14, 2019
Istio 1.4 Upgrade Notes
Important changes to consider when upgrading to Istio 1.4.
Nov 14, 2019
Istio 1.4 Change Notes
Istio 1.4 release notes.
Nov 11, 2019
Support for Istio 1.2 ends on December 13th, 2019
Upcoming Istio 1.2 end of life announcement.
Nov 11, 2019
Announcing Istio 1.3.5
Istio 1.3.5 patch release.
Nov 7, 2019
ISTIO-SECURITY-2019-006
Denial of service.
Nov 6, 2019
Announcing Istio 1.2.9
Istio 1.2.9 patch release.
Nov 1, 2019
Announcing Istio 1.3.4
Istio 1.3.4 patch release.
Oct 23, 2019
Announcing Istio 1.2.8
Istio 1.2.8 patch release.
Oct 21, 2019
Support for Istio 1.1 has ended
Istio 1.1 end of life announcement.
Oct 21, 2019
Announcing Istio 1.1.17
Istio 1.1.17 patch release.
Oct 14, 2019
Announcing Istio 1.3.3
Istio 1.3.3 patch release.
Oct 8, 2019
ISTIO-SECURITY-2019-005
Denial of service caused by the presence of numerous HTTP headers in client requests.
Oct 8, 2019
Announcing Istio 1.3.2
Istio 1.3.2 patch release.
Oct 8, 2019
Announcing Istio 1.2.7
Istio 1.2.7 patch release.
Oct 8, 2019
Announcing Istio 1.1.16
Istio 1.1.16 patch release.
Sep 27, 2019
Announcing Istio 1.3.1
Istio 1.3.1 patch release.
Sep 17, 2019
Announcing Istio 1.2.6
Istio 1.2.6 patch release.
Sep 16, 2019
Announcing Istio 1.1.15
Istio 1.1.15 patch release.
Sep 12, 2019
Announcing Istio 1.3
Istio 1.3 release announcement.
Sep 12, 2019
Istio 1.3 Helm Changes
Details the Helm chart installation options differences between Istio 1.2 and Istio 1.3.
Sep 12, 2019
Istio 1.3 Upgrade Notes
Important changes to consider when upgrading to Istio 1.3.
Sep 12, 2019
Istio 1.3 Change Notes
Istio 1.3 release notes.
Sep 10, 2019
Istio 1.2.4 sidecar image vulnerability
An erroneous 1.2.4 sidecar image was available due to a faulty release operation.
Affected versions: 1.2 to 1.2.4Aug 26, 2019
Announcing Istio 1.2.5
Istio 1.2.5 patch release.
Aug 26, 2019
Announcing Istio 1.1.14
Istio 1.1.14 patch release.
Aug 15, 2019
Support for Istio 1.1 ends on September 19th, 2019
Upcoming Istio 1.1 end of life announcement.
Aug 13, 2019
ISTIO-SECURITY-2019-004
Multiple denial of service vulnerabilities related to HTTP2 support in Envoy.
Aug 13, 2019
ISTIO-SECURITY-2019-003
Denial of service in regular expression parsing.
Aug 13, 2019
Announcing Istio 1.2.4
Istio 1.2.4 patch release.
Aug 13, 2019
Announcing Istio 1.1.13
Istio 1.1.13 patch release.
Aug 2, 2019
Announcing Istio 1.2.3
Istio 1.2.3 patch release.
Aug 2, 2019
Announcing Istio 1.1.12
Istio 1.1.12 patch release.
Jul 3, 2019
Announcing Istio 1.1.11
Istio 1.1.11 patch release.
Jun 28, 2019
ISTIO-SECURITY-2019-002
Denial of service affecting JWT access token parsing.
Jun 28, 2019
Announcing Istio 1.2.2
Istio 1.2.2 patch release.
Jun 28, 2019
Announcing Istio 1.1.10
Istio 1.1.10 patch release.
Jun 28, 2019
Announcing Istio 1.0.9
Istio 1.0.9 patch release.
Jun 27, 2019
Announcing Istio 1.2.1
Istio 1.2.1 patch release.
Jun 19, 2019
Support for Istio 1.0 has ended
Istio 1.0 end of life announcement.
Jun 18, 2019
Announcing Istio 1.2
Istio 1.2 release announcement.
Jun 18, 2019
Istio 1.2 Helm Changes
Details the Helm chart installation options differences between Istio 1.1 and Istio 1.2.
Jun 18, 2019
Istio 1.2 Upgrade Notes
Important changes operators must understand before upgrading to Istio 1.2.
Jun 18, 2019
Istio 1.2 Change Notes
Istio 1.2 release notes.
Jun 17, 2019
Announcing Istio 1.1.9
Istio 1.1.9 patch release.
Jun 7, 2019
Announcing Istio 1.0.8
Istio 1.0.8 patch release.
Jun 6, 2019
Announcing Istio 1.1.8
Istio 1.1.8 patch release.
May 28, 2019
ISTIO-SECURITY-2019-001
Incorrect access control.
May 23, 2019
Support for Istio 1.0 ends on June 19th, 2019
Upcoming Istio 1.0 end of life announcement.
May 17, 2019
Announcing Istio 1.1.7
Istio 1.1.7 patch release.
May 11, 2019
Announcing Istio 1.1.6
Istio 1.1.6 patch release.
May 3, 2019
Announcing Istio 1.1.5
Istio 1.1.5 patch release.
Apr 24, 2019
Announcing Istio 1.1.4
Istio 1.1.4 patch release.
Apr 15, 2019
Announcing Istio 1.1.3
Istio 1.1.3 patch release.
Apr 5, 2019
Announcing Istio 1.1.2 with Important Security Update
Istio 1.1.2 patch release.
Apr 5, 2019
Announcing Istio 1.0.7 with Important Security Update
Istio 1.0.7 patch release.
Mar 25, 2019
Announcing Istio 1.1.1
Istio 1.1.1 patch release.
Mar 19, 2019
Announcing Istio 1.1
Istio 1.1 release announcement.
Mar 19, 2019
Istio 1.1 Helm Changes
Details the Helm chart installation options differences between Istio 1.0 and Istio 1.1.
Mar 19, 2019
Istio 1.1 Upgrade Notes
Important changes operators must understand before upgrading to Istio 1.1.
Mar 19, 2019
Istio 1.1 Change Notes
Istio 1.1 release notes.
Feb 12, 2019
Announcing Istio 1.0.6
Istio 1.0.6 patch release.
Dec 20, 2018
Announcing Istio 1.0.5
Istio 1.0.5 patch release.
Nov 21, 2018
Announcing Istio 1.0.4
Istio 1.0.4 patch release.
Oct 30, 2018
Announcing Istio 1.0.3
Istio 1.0.3 patch release.
Sep 6, 2018
Announcing Istio 1.0.2
Istio 1.0.2 patch release.
Aug 29, 2018
Announcing Istio 1.0.1
Istio 1.0.1 patch release.
Jul 31, 2018
Announcing Istio 1.0
Istio is ready for production use with its 1.0 release.
Jun 1, 2018
Announcing Istio 0.8
Istio 0.8 announcement.
Mar 28, 2018
Announcing Istio 0.7
Istio 0.7 announcement.
Mar 8, 2018
Announcing Istio 0.6
Istio 0.6 announcement.
Feb 2, 2018
Announcing Istio 0.5
Istio 0.5 announcement.
Dec 18, 2017
Announcing Istio 0.4
Istio 0.4 announcement.
Nov 29, 2017
Announcing Istio 0.3
Istio 0.3 announcement.
Oct 10, 2017
Announcing Istio 0.2
Istio 0.2 announcement.
May 24, 2017
Introducing Istio
Istio 0.1 announcement.