Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain multiple values. An attacker could craft requests with multiple header values in a way that causes Envoy to evaluate the header differently than intended, potentially bypassing authorization checks. This may allow unauthorized requests to reach protected services when policies depend on such header-based matching conditions. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.
Cite this page
CVE-2026-31838. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-31838
Use CWE-863, Istio vendor hub and Istio product page to widen CVE-2026-31838 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2026-31837 and CVE-2021-39156 for nearby disclosures in the same product family.