Istio
1.30.4Networking & MessagingEnvoyとIstioに関するセキュリティ修正を中心とした保守リリースです。信頼性や正確性の修正に加え、利用しているプロトコルや設定によっては運用上の確認が必要な挙動変更も含まれます。
要対応 (2)
securityパラメーター付きパスセグメントのURL正規化を修正
CVE-2026-73551において、パラメーター付きのドットおよびドットドットのパスセグメントに対するURL正規化を修正しました。
securityセグメント単位のパラメーターを含むパスのマッチングを修正
CVE-2026-73511において、セグメント単位のパラメーターを含むパスのマッチングを修正しました。
影響確認 (16)
securityHTTP/2トレーラー処理の解放後使用を修正
HTTP/2を使用している場合に適用されます。
CVE-2026-73513において、HTTP/2トレーラーを
END_STREAMフラグなしで受信した際にoghttp2で発生するヒープ領域の解放後使用を修正しました。security
safe_regexのヘッダー検査を修正safe_regexを設定している場合に適用されます。CVE-2026-73552において、負のマッチ条件を持つRBACポリシーで、ヘッダーにUTF-8ではないバイト列が含まれると
safe_regexが検査をすり抜ける問題を修正しました。securityQUIC HTTPデータグラム処理の解放後使用を修正
QUICのHTTPデータグラムハンドラーを使用している場合に適用されます。
CVE-2026-73512において、QUICのHTTPデータグラムハンドラーで発生する解放後使用を修正しました。
security
ext_authzのCONNECTリクエスト処理を修正ext_authzを使用している場合に適用されます。CVE-2026-73547において、
:pathヘッダーのないCONNECTリクエストをext_authzが処理した際の異常終了を修正しました。securityHTTP/3のIPv6クライアントアドレス処理を修正
HTTP/3を使用している場合に適用されます。
CVE-2026-73549において、HTTP/3でスコープ付きIPv6クライアントアドレスを処理した際の異常終了を修正しました。
security
ext_authzraw HTTPクライアントの解放後使用を修正ext_authzを使用している場合に適用されます。CVE-2026-50572において、
ext_authzのraw HTTPクライアントで発生する解放後使用を修正しました。securityHTML統計インターフェースのXSSを修正
HTML統計インターフェースを公開している場合に適用されます。
CVE-2026-73546において、HTML統計インターフェースに保存されるクロスサイトスクリプティングの脆弱性を修正しました。
securityHTTP/3接続プール選択時のヌルポインタ参照を修正
HTTP/3を使用している場合に適用されます。
CVE-2026-48521において、ALPNに基づくHTTP/3接続プール選択中に発生するヌルポインタ参照を修正しました。
security汎用HTTPアップグレードのレスポンス汚染を修正
汎用HTTPアップグレードを使用している場合に適用されます。
CVE-2026-73548において、汎用HTTPアップグレードで発生するユーザー間のレスポンス汚染を修正しました。
security重複HostヘッダーによるHTTP/2のメモリ枯渇を修正
HTTP/2を使用している場合に適用されます。
CVE-2026-73550において、破棄された重複Hostヘッダーを利用したHTTP/2のメモリ枯渇を修正しました。
securityパスパラメーター無視設定によるRBACバイパスを修正
ignore_path_parameters_in_path_matchingを設定している場合に適用されます。CVE-2026-73553において、
ignore_path_parameters_in_path_matchingを利用したRBACのバイパスを修正しました。security
BackendTLSPolicyの平文フォールバックを修正適用対象はリリースノートに明記されていません。
GHSA-qm8v-g4f9-qhjxにおいて、CA参照を解決できない場合に、サイドカープロキシ上の
BackendTLSPolicyが平文通信へフォールバックする問題を修正しました。securityXDS APIジェネレーターの認証を既定で有効化
XDS APIジェネレーター(MCP設定提供)を実行している場合に適用されます。
XDS APIジェネレーター(MCP設定提供)が、検証済みのコントロールプレーンIDを要求するようになりました。従来はIstiodのXDSポートへ到達できるクライアントが全名前空間のIstio設定を読み取れました。既定値は
ENABLE_XDS_API_GENERATOR_AUTH=trueで、互換性のために無効化する場合はENABLE_XDS_API_GENERATOR_AUTH=falseを指定します。securityGateway APIの名前空間間参照の認可順序を修正
適用対象はリリースノートに明記されていません。
Gateway APIで、名前空間をまたぐTLS証明書の
certificateRefまたはcaCertificateRefが、ReferenceGrantの認可確認より先に解決される問題を修正しました。認可を先に行い、許可されていない名前空間間参照にはRefNotPermittedを返します。これにより、参照先のSecretまたはConfigMapが存在するかどうかが、許可のない参照からResolvedRefsステータスに現れなくなります。security
jwksUri取得時のSSRF対策を強化jwksUriを設定している場合に適用されます。RequestAuthenticationの
jwksUri取得にあったSSRFの隙間を修正しました。Istiodは既定で、リンクローカルアドレスと既知のクラウドメタデータアドレス(169.など)への接続をダイヤル時に遮断し、取得した応答が有効なJWKSでない場合も拒否します。プライベートアドレスとループバックアドレスへの接続は引き続き可能で、254. 169. 254 BLOCKED_CIDRS_IN_JWKS_URISで遮断できます。securityサイドカー注入アノテーションの出力エスケープを修正
sidecar.のistio. io/* proxyImage、bootstrapOverride、logLevel、componentLogLevel、agentLogLevelのいずれかを設定している場合に適用されます。sidecar.のistio. io/* proxyImage、bootstrapOverride、logLevel、componentLogLevel、agentLogLevelアノテーションが、出力エスケープなしでサイドカーまたはゲートウェイの注入テンプレートへ展開される問題を修正しました。各アノテーションは、テンプレートのすべての出力先で一貫してエスケープされます。
その他の記録済み変更 15 件すべてfixes 14 · constraints 1
fixes (14)
- - Fixed a deadlock where the istio-cni node agent pod could fail to start (for example after a node reboot) because the CNI plugin only skipped the Kubernetes client creation for its own agent pod when ambient mode was enabled. The preemptive check now runs in sidecar mode as well, so the agent pod no longer blocks on a kubeconfig it has not written yet. ( Issue #60668 )
- - Fixed a bug where a remote cluster’s network gateway could disappear from cross-network routing after credential rotation and not recover until istiod restarted. The in-place registry swap now re-wires the new registry to the aggregate controller’s handlers so its future gateway and service events propagate, and reloads gateways once to pick up those discovered during the pre-swap sync. ( Issue #60920 )
- - Fixed an issue in multicluster deployments where rotating a remote cluster’s istio-remote-secret could permanently wipe endpoint shards for services with stable endpoints in that cluster, making them unreachable across clusters until istiod was restarted. ( Issue #61043 )
- - Fixed a race condition on istiod startup where the readiness probe could report ready before the dedicated injection and validation webhook server ( --httpsAddr , default :15017 ) was accepting connections, causing intermittent failed calling webhook timeouts when creating resources immediately after istiod became ready. This does not affect deployments where webhooks share the main HTTP server (empty --httpsAddr ). ( Issue #61049 )
- - Fixed an issue where ingress gateways bypassed waypoint proxies for multi-cluster services when remote workloads were on a different network, causing authorization policies to not be enforced. ( Issue #61092 )
- - Fixed an issue where gateway proxy Deployment resources could permanently fail to be created during istiod startup. ( Issue #61095 )
- - Fixed an issue where a pod selected by a ServiceEntry workloadSelector could start up missing that service from its sidecar’s inbound configuration. Traffic to the port was not handled as the protocol declared in the ServiceEntry , and port-level PeerAuthentication was not applied. The pod did not recover on its own; only restarting istiod repaired it. ( Issue #61157 )
- - Fixed an issue where istio-cni considered hostNetwork pods eligible for ambient enrollment. ( Issue #61168 )
- - Fixed a file descriptor leak in the istio-cni node agent: when the procfs scan found more than one network namespace for the same pod, the losing candidate’s netns file descriptor was dropped without being closed, pinning the namespace in the kernel until garbage collection.
- - Fixed external SDS providers configured through extensionProviders to use the configured service hostname as the gRPC authority.
- - Fixed a goroutine leak in istiod leader election where every election cycle (leadership lost and re-acquired) leaked one goroutine until process exit. ( Issue #60843 )
- - Fixed an issue where istiod CPU usage increased as the number of AuthorizationPolicy resources increased. ( Issue #61254 )
- - Fixed ListenerSet conflict resolution for hostname and protocol conflicts. Conflicting listeners are now correctly rejected and ListenerSet status conditions report in compliance with Gateway API 1.5. ( PR #60775 )
- - Fixed a bug where a ztunnel reconnect (such as the periodic connection recycle from keepaliveMaxServerConnectionAge ) triggered a full workload (WDS) push. Istiod now assigns each WDS resource a content-based version and, when a reconnecting client reports the versions it already holds via initial_resource_versions , re-sends only resources that changed while the client was disconnected. Older ztunnel versions that do not report versions continue to receive the full set. ( Issue #1966 )
constraints (1)
- - Fixed an EnvoyFilter validation gap where an uncapped proxyVersion match expression could drive excessive istiod memory and CPU during regex compilation. The match expression is now limited to 1024 characters. Credit : This issue was reported by Artem Cherezov .
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。