Istio
1.27.7Networking & MessagingFeb 16, 2026
Istio 1.27.7 is a security-focused release addressing two vulnerabilities. The fixes concern cgo comment parsing and `crypto/tls` session resumption.
Action needed (2)
securitycriticalCVE-2025-68121 session resumption flaw
Istio 1.27.7 addresses a
crypto/tlssession resumption flaw. Resumed handshakes no longer succeed whenClientCAsorRootCAsare mutated between the initial and resumed handshake. Advisory: CVE-2025-68121.securityhighCVE-2025-61732 comment parsing vulnerability
Istio 1.27.7 addresses a discrepancy between Go and C/C++ comment parsing that allowed code smuggling into the resulting cgo binary. Advisory: CVE-2025-61732.
Add Istio to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.