Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.
Cite this page
CVE-2026-31837. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-31837
Use CWE-200, Istio vendor hub and Istio product page to widen CVE-2026-31837 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2021-39156 and CVE-2022-39388 for nearby disclosures in the same product family.