Incorrect Regular Expression Affecting cert-manager-istio-csr package, versions *


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

Social Trends
EPSS
0.21% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-CERTMANAGERISTIOCSR-16113418
  • published21 Apr 2026
  • disclosed15 Apr 2026

Introduced: 15 Apr 2026

CVE-2026-39350  (opens in a new tab)
CWE-185  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

There is no fixed version for Minimos:latest cert-manager-istio-csr.

NVD Description

Note: Versions mentioned in the description apply only to the upstream cert-manager-istio-csr package and not the cert-manager-istio-csr package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1, the serviceAccounts and notServiceAccounts fields in AuthorizationPolicy incorrectly interpret dots (.) as a regular expression matcher. Because . is a valid character in a service account name, an AuthorizationPolicy ALLOW rule targeting a service account such as cert-manager.io also matches cert-manager-io, cert-managerXio, etc. A DENY rule targeting the same name fails to block those variants. Fixes are available in versions 1.29.2, 1.28.6, and 1.27.9.