Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. istio.io/istio
  4. ›
  5. CVE-2026-41413

CVE-2026-41413: Istio: SSRF via RequestAuthentication jwksUri

April 16, 2026 (updated May 8, 2026)

When a RequestAuthentication resource is created with a jwksUri pointing to an internal service, istiod makes an unauthenticated HTTP GET request to that URL without filtering out localhost or link local ips. This can result in sensitive data being distributed to Envoy proxies via xDS configuration.

Note: a partial mitigation for this was released in 1.29.1, 128.5, and 1.27.8; however, it was incomplete and missed a few codepaths. 1.29.2 and 1.28.6 contain the more robust fix.

References

  • github.com/advisories/GHSA-fgw5-hp8f-xfhc
  • github.com/istio/istio
  • github.com/istio/istio/releases/tag/1.28.6
  • github.com/istio/istio/releases/tag/1.29.2
  • github.com/istio/istio/security/advisories/GHSA-fgw5-hp8f-xfhc
  • nvd.nist.gov/vuln/detail/CVE-2026-41413

Code Behaviors & Features

Detect and mitigate CVE-2026-41413 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.0.0-20260410004459-189832a289c1

Fixed versions

  • 0.0.0-20260410004459-189832a289c1

Solution

Upgrade to version 0.0.0-20260410004459-189832a289c1 or above.

Impact 5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

go/istio.io/istio/CVE-2026-41413.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:18:18 +0000.