Loading
Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authorization rules are used.
Cite this page
CVE-2021-31920. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2021-31920
Use CWE-706, Istio vendor hub and Istio product page to widen CVE-2021-31920 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2026-31837 and CVE-2021-39156 for nearby disclosures in the same product family.