{"api_version":"v1","generated_at":"2026-10-08T17:50:00+00:00","product":{"cve_count":13,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-istio-istio-d26fe01a54c2","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/istio","name":"istio","next_cursor":null,"observations":[{"affected":"< 1.28.6; >= 1.29.0-alpha.0, < 1.29.2","affected_versions_present":true,"cve_id":"CVE-2026-41413","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41413","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-07T12:59:35.159Z","patch_url":"https://github.com/istio/istio/security/advisories/GHSA-fgw5-hp8f-xfhc","primary_source":"","published":"2026-05-07T04:18:32.040Z"},{"affected":">= 1.25.0, < < 1.27.9; >= 1.28.0, < 1.28.6; >= 1.29.0, < 1.29.2","affected_versions_present":true,"cve_id":"CVE-2026-39350","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39350","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-16T12:04:54.038Z","patch_url":"","primary_source":"","published":"2026-04-15T22:42:24.216Z"},{"affected":">= 1.29.0-alpha.0, < 1.29.1; >= 1.28.0-alpha.0, < 1.28.5; < 1.27.8","affected_versions_present":true,"cve_id":"CVE-2026-31838","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31838","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-07T02:39:59.774Z","patch_url":"","primary_source":"","published":"2026-03-10T21:58:53.354Z"},{"affected":">= 1.29.0-alpha.0, < 1.29.1; >= 1.28.0-alpha.0, < 1.28.5; < 1.27.8","affected_versions_present":true,"cve_id":"CVE-2026-31837","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31837","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-20T12:04:43.711Z","patch_url":"","primary_source":"","published":"2026-03-10T21:57:44.387Z"},{"affected":">= 1.15.0-beta.0, < 1.15.3","affected_versions_present":true,"cve_id":"CVE-2022-39388","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-39388","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T16:39:23.029Z","patch_url":"https://github.com/istio/istio/commit/346260e5115e9fbc65ba8a559bc686e6ca046a32","primary_source":"","published":"2022-11-10T00:00:00.000Z"},{"affected":"< 1.13.9; >= 1.14.0, < 1.14.5; >= 1.15.0, < 1.15.2","affected_versions_present":true,"cve_id":"CVE-2022-39278","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-39278","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T16:50:32.655Z","patch_url":"","primary_source":"","published":"2022-10-13T00:00:00.000Z"},{"affected":"< 1.12.18; >= 1.13.0, < 1.13.5; >= 1.14.0, < 1.14.1","affected_versions_present":true,"cve_id":"CVE-2022-31045","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31045","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T18:17:15.176Z","patch_url":"","primary_source":"","published":"2022-06-09T20:55:10.000Z"},{"affected":"< 1.11.8,; >= 1.12.0, < 1.12.5; >= 1.13.0, < 1.13.2","affected_versions_present":true,"cve_id":"CVE-2022-24726","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24726","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:55:37.983Z","patch_url":"https://github.com/golang/go/issues/51112","primary_source":"","published":"2022-03-10T20:45:12.000Z"},{"affected":">= 1.13.0, < 1.13.1; >= 1.12.0, < 1.12.4; < 1.11.7","affected_versions_present":true,"cve_id":"CVE-2022-23635","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23635","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T19:02:00.579Z","patch_url":"https://github.com/istio/istio/commit/5f3b5ed958ae75156f8656fe7b3794f78e94db84","primary_source":"","published":"2022-02-22T22:00:13.000Z"},{"affected":">= 1.12.0, < 1.12.2","affected_versions_present":true,"cve_id":"CVE-2022-21701","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-21701","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T19:09:59.126Z","patch_url":"https://istio.io/latest/news/releases/1.12.x/announcing-1.12.2/","primary_source":"","published":"2022-01-19T21:40:10.000Z"},{"affected":">= 1.12.0, < 1.12.2","affected_versions_present":true,"cve_id":"CVE-2022-21679","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-21679","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T19:10:05.311Z","patch_url":"","primary_source":"","published":"2022-01-19T21:35:10.000Z"},{"affected":"< 1.9.8; >= 1.10.0, < 1.10.4; >= 1.11.0, < 1.11.1","affected_versions_present":true,"cve_id":"CVE-2021-39156","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-39156","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T01:58:18.136Z","patch_url":"","primary_source":"","published":"2021-08-24T22:30:12.000Z"},{"affected":"<= 1.9.8; >= 1.10.0, < 1.10.4; >= 1.11.0, < 1.11.1","affected_versions_present":true,"cve_id":"CVE-2021-39155","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-39155","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T01:58:18.140Z","patch_url":"","primary_source":"","published":"2021-08-24T22:25:18.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"istio"}}
