istio-1.27

Direct Vulnerabilities

Known vulnerabilities in the istio-1.27 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-gcjh-h69q-9w9g

<1.27.9-r5
  • L
GHSA-hrxh-6v49-42gf

<1.27.9-r4
  • L
GHSA-4279-q6mj-392r

<1.27.9-r3
  • L
CVE-2026-39822

<1.27.9-r3
  • L
CVE-2026-42505

<1.27.9-r3
  • L
CVE-2026-42504

<1.27.9-r3
  • L
GHSA-ff52-ph69-cf7x

<1.27.9-r3
  • L
CVE-2026-27145

<1.27.9-r3
  • L
GHSA-h3gm-q7m7-mp28

<1.27.9-r3
  • L
GHSA-h524-452v-82p9

<1.27.9-r3
  • L
CVE-2026-42507

<1.27.9-r3
  • L
GHSA-xcgv-8mv7-v8c7

<1.27.9-r3
  • L
GHSA-fgw5-hp8f-xfhc

<1.27.9-r0
  • H
Server-Side Request Forgery (SSRF)

<1.27.9-r0
  • L
GHSA-f5wc-c3c7-36mc

<1.27.9-r2
  • L
GHSA-9m57-25v3-79x9

<1.27.9-r2
  • L
GHSA-w879-237q-wc7r

<1.27.9-r2
  • L
GHSA-45gg-vh54-h5m9

<1.27.9-r2
  • L
GHSA-78mq-xcr3-xm33

<1.27.9-r2
  • L
GHSA-89gr-r52h-f8rx

<1.27.9-r2
  • L
GHSA-vgwf-h737-ff37

<1.27.9-r2
  • L
GHSA-x527-x647-q7gg

<1.27.9-r2
  • L
GHSA-q4h4-gmj2-qvw2

<1.27.9-r2
  • L
GHSA-5cgq-3rg8-m6cv

<1.27.9-r2
  • L
GHSA-rm3j-f69w-wqmq

<1.27.9-r2
  • L
GHSA-qpw4-5x99-6vjp

<1.27.9-r2
  • L
GHSA-jppx-rxg9-jmrx

<1.27.9-r2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.27.9-r2
  • L
GHSA-hfvc-g4fc-pqhx

<1.27.9-r2
  • L
GHSA-5cv4-jp36-h3mw

<1.27.9-r2
  • L
GHSA-mh2q-q3fh-2475

<1.27.9-r2
  • L
GHSA-wrh2-89vg-4j9g

<1.27.9-r2
  • L
Improper Certificate Validation

<1.27.9-r2
  • L
Out-of-Bounds

<1.27.9-r2
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.27.9-r2
  • L
Incorrect Type Conversion or Cast

<1.27.9-r2
  • L
CVE-2026-46598

<1.27.9-r2
  • L
Resource Exhaustion

<1.27.9-r2
  • L
CVE-2026-46595

<1.27.9-r2
  • L
GHSA-cg87-vwwh-xvgj

<1.27.9-r2
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1.27.9-r2
  • L
Uncaught Exception

<1.27.9-r2
  • L
Cross-site Scripting (XSS)

<1.27.9-r2
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.27.9-r2
  • L
Allocation of Resources Without Limits or Throttling

<1.27.9-r2
  • H
Untrusted Search Path

<1.27.9-r2
  • L
Missing Authorization

<1.27.9-r2
  • L
Integer Overflow or Wraparound

<1.27.9-r2
  • L
Missing Authorization

<1.27.9-r2
  • L
Deserialization of Untrusted Data

<1.27.9-r2
  • L
Improper Certificate Validation

<1.27.9-r2
  • L
GHSA-pc3f-x583-g7j2

<1.27.9-r2
  • L
Improper Verification of Cryptographic Signature

<1.27.9-r2
  • L
GHSA-w9p8-pvxh-rxpj

<1.27.9-r2
  • L
GHSA-78h2-9frx-2jm8

<1.27.9-r2
  • L
GHSA-m9x8-m34x-fj9q

<1.27.9-r2
  • L
Improper Certificate Validation

<1.27.9-r2
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.27.9-r2
  • L
Allocation of Resources Without Limits or Throttling

<1.27.9-r2
  • L
GHSA-h74g-238j-357m

<1.27.9-r1
  • L
GHSA-xj38-jxc5-rppx

<1.27.9-r1
  • L
Improper Encoding or Escaping of Output

<1.27.9-r1
  • L
GHSA-gjvh-7jh8-7xhm

<1.27.9-r1
  • M
Link Following

<1.27.9-r1
  • H
Allocation of Resources Without Limits or Throttling

<1.27.9-r1
  • L
GHSA-8g2r-hhvj-mv99

<1.27.9-r1
  • L
GHSA-5m4p-2gjx-p2g8

<1.27.9-r1
  • L
GHSA-2283-wf8c-rw8r

<1.27.9-r1
  • M
Allocation of Resources Without Limits or Throttling

<1.27.9-r1
  • L
GHSA-cqrx-3m42-5p5w

<1.27.9-r1
  • L
GHSA-m4pr-4j3g-9v7v

<1.27.9-r1
  • L
CVE-2026-42501

<1.27.9-r1
  • H
Allocation of Resources Without Limits or Throttling

<1.27.9-r1
  • H
NULL Pointer Dereference

<1.27.9-r1
  • H
Improper Certificate Validation

<1.27.9-r1
  • L
CVE-2026-39825

<1.27.9-r1
  • M
Out-of-bounds Write

<1.27.9-r1
  • L
Cross-site Scripting (XSS)

<1.27.9-r1
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1.27.9-r1
  • L
GHSA-x4jj-h2v8-hqqv

<1.27.9-r1
  • H
Incorrect Authorization

<1.27.9-r1
  • C
CVE-2026-27143

<1.27.9-r1
  • L
GHSA-7mr4-xjxg-34g6

<1.27.9-r1
  • L
GHSA-xq5j-9r39-c3vf

<1.27.9-r1
  • M
Cross-site Scripting (XSS)

<1.27.9-r1
  • L
GHSA-qf3q-3h68-mmh2

<1.27.9-r1
  • L
CVE-2026-42499

<1.27.9-r1
  • L
GHSA-qc64-m6c2-v4x7

<1.27.9-r1
  • L
GHSA-5w89-2c2x-6x66

<1.27.9-r1
  • L
GHSA-jrg3-gfjw-hm96

<1.27.9-r1
  • L
GHSA-cfp9-33rc-j74f

<1.27.9-r1
  • L
GHSA-p9h5-jm8x-mjm5

<1.27.9-r1
  • L
CVE-2026-32280

<1.27.9-r1
  • L
GHSA-3v2c-x6q9-f697

<1.27.9-r1
  • M
Link Following

<1.27.9-r1
  • L
GHSA-497x-jcxf-m478

<1.27.9-r1
  • H
Double Free

<1.27.9-r1
  • L
GHSA-p77j-4mvh-x3m3

<1.27.8-r1
  • L
Improper Authorization

<1.27.8-r1
  • H
CVE-2025-15558

<1.27.7-r2
  • L
GHSA-p436-gjf2-799p

<1.27.7-r2
  • L
GHSA-9h8m-3fm2-qjrq

<1.27.7-r1
  • L
Untrusted Search Path

<1.27.7-r1
  • L
GHSA-jv3w-x3r3-g6rm

<1.27.4-r1
  • L
Information Exposure

<1.27.4-r1
  • L
GHSA-f6x5-jh6r-wrfv

<1.27.3-r2
  • L
CVE-2025-47914

<1.27.3-r2
  • L
GHSA-j5w8-q4qc-rx2x

<1.27.3-r2
  • L
CVE-2025-58181

<1.27.3-r2
  • L
Use of Uninitialized Resource

<1.27.0-r2
  • L
Allocation of Resources Without Limits or Throttling

<1.27.0-r2