Istio
1.29.7Networking & Messaging여러 `Envoy` 및 `Istio` 보안 취약점을 수정하고, 인증과 기본 동작을 변경한 보안 중심 유지보수 릴리스입니다. 정확성과 성능에 관한 수정도 포함되어 있습니다.
조치 필요 (3)
security매개변수가 포함된 경로 구간의
URL정규화 수정매개변수가 포함된 점 및 두 점 경로 구간의
URL정규화를 수정했습니다. CVE-2026-73551에 해당합니다.security구간별 매개변수 경로 일치 수정
구간별 매개변수가 있는 경로 일치 처리를 수정했습니다. CVE-2026-73511에 해당합니다.
security일반
HTTP업그레이드의 사용자 간 응답 오염 수정일반
HTTP업그레이드에서 사용자 간 응답 오염이 발생하던 문제를 수정했습니다. CVE-2026-73548에 해당합니다.
영향 확인 (17)
security
HTTP/2트레일러 처리 중 힙 해제 후 사용 수정HTTP/2를 사용하는 경우에 해당합니다.HTTP/2트레일러가END_STREAM플래그 없이 들어올 때oghttp2에서 발생하던 힙 해제 후 사용 문제를 수정했습니다. CVE-2026-73513에 해당합니다.security음수 일치
RBAC정책의safe_regex검사 수정음수가 일치하는
RBAC정책을 사용하는 경우에 해당합니다.음수가 일치하는
RBAC정책에서safe_regex가UTF-8이 아닌 헤더 바이트를 허용하던 문제를 수정했습니다. CVE-2026-73552에 해당합니다.security
QUICHTTP데이터그램 처리기의 해제 후 사용 수정QUICHTTP데이터그램 처리기를 사용하는 경우에 해당합니다.QUICHTTP데이터그램 처리기에서 발생하던 해제 후 사용 문제를 수정했습니다. CVE-2026-73512에 해당합니다.security
:path없는CONNECT요청의ext_authz비정상 종료 수정ext_authz를 사용하는 경우에 해당합니다.:path헤더가 없는CONNECT요청을 처리할 때ext_authz가 비정상 종료하던 문제를 수정했습니다. CVE-2026-73547에 해당합니다.security
HTTP/3의 범위 지정IPv6주소 처리 수정HTTP/3를 사용하는 경우에 해당합니다.HTTP/3에서 범위가 지정된IPv6클라이언트 주소를 처리할 때 비정상 종료하던 문제를 수정했습니다. CVE-2026-73549에 해당합니다.security
ext_authz원시HTTP클라이언트의 해제 후 사용 수정ext_authz원시HTTP클라이언트를 사용하는 경우에 해당합니다.ext_authz원시HTTP클라이언트에서 발생하던 해제 후 사용 문제를 수정했습니다. CVE-2026-50572에 해당합니다.security
HTML stats interface의 저장형 사이트 간 스크립팅 수정HTML stats interface를 사용하는 경우에 해당합니다.HTML stats interface에 저장형 사이트 간 스크립팅 취약점이 있던 문제를 수정했습니다. CVE-2026-73546에 해당합니다.security
HTTP/3연결 풀 선택 중 널 포인터 역참조 수정HTTP/3를 사용하는 경우에 해당합니다.ALPN기반HTTP/3연결 풀을 선택하는 과정에서 널 포인터를 역참조하던 문제를 수정했습니다. CVE-2026-48521에 해당합니다.security중복
Host헤더로 인한HTTP/2메모리 고갈 수정HTTP/2를 사용하는 경우에 해당합니다.중복된
Host헤더를 버리는 과정에서HTTP/2메모리가 고갈될 수 있던 문제를 수정했습니다. CVE-2026-73550에 해당합니다.security
ignore_path_parameters_in_path_matching을 통한RBAC우회 수정ignore_path_parameters_in_path_matching을 설정한 경우에 해당합니다.ignore_path_parameters_in_path_matching설정을 이용해RBAC를 우회할 수 있던 문제를 수정했습니다. CVE-2026-73553에 해당합니다.security
BackendTLSPolicy의 확인되지 않은CA reference처리 수정BackendTLSPolicy를 설정하고sidecar프록시를 실행하면서CA reference를 지정하지 않은 경우에 해당합니다.CA reference를 확인하지 못한sidecar프록시에서BackendTLSPolicy가 평문 통신으로 허용되던 문제를 수정했습니다. GHSA-qm8v-g4f9-qhjx에 해당합니다.security
EnvoyFilter일치 표현식 길이 제한일치 표현식이 있는
EnvoyFilter를 설정한 경우에 해당합니다.EnvoyFilter의 일치 표현식 길이를 1024자로 제한했습니다.security
ingress gateways인증 정책 적용 수정ingress gateways를 실행하는 경우에 해당합니다.ingress gateways에서 인증 정책이 적용되지 않던 문제를 수정했습니다.security
Gateway API의ResolvedRefs정보 노출 수정Gateway API를 사용하는 경우에 해당합니다.권한 부여가 참조를 허용하지 않아도 리스너의
ResolvedRefs상태에서 참조된Secret또는ConfigMap의 존재 여부가 드러날 수 있던 문제를 수정했습니다.security
istiodjwksUri요청의SSRF수정istiod를 실행하고jwksUri를 설정한 경우에 해당합니다.istiod의RequestAuthentication에서jwksUri를 가져올 때 발생하던SSRF허점을 수정했습니다.security
ENABLE_XDS_API_GENERATOR_AUTH기본값 변경ENABLE_XDS_API_GENERATOR_AUTH를 설정하지 않은 경우에 해당합니다.ENABLE_XDS_API_GENERATOR_AUTH의 기본값을true로 변경했습니다. 호환성을 위해 필요한 경우ENABLE_XDS_API_GENERATOR_AUTH=false로 끌 수 있습니다.security사이드카 및 게이트웨이 주입 템플릿의 주석 처리 수정
proxyImage,bootstrapOverride,logLevel,componentLogLevel,agentLogLevel가운데 하나라도 설정한 경우에 해당합니다.proxyImage,bootstrapOverride,logLevel,componentLogLevel,agentLogLevel이 사이드카 및 게이트웨이 주입 템플릿에 출력 이스케이프 없이 삽입되던 문제를 수정했습니다.
그 외 기록된 변경 13건 전체fixes 11 · value changes 2
fixes (11)
- Fixed a race condition on istiod startup where the readiness probe could report ready before the dedicated injection and validation webhook server ( --httpsAddr , default :15017 ) was accepting connections
- Fixed an issue where gateway proxy Deployment resources could permanently fail to be created during istiod startup.
- Fixed an issue where istio-cni considered hostNetwork pods eligible for ambient enrollment.
- Fixed a file descriptor leak in the istio-cni node agent
- Fixed a bug where the istio-cni node agent could pair an ambient pod with another pod’s network namespace
- Fixed an issue where istiod permanently retained a copy of every workload resource name
- Fixed a bug where a ztunnel reconnect (such as the periodic connection recycle from keepaliveMaxServerConnectionAge ) triggered a full workload (WDS) push.
- Fixed goroutine and memory leaks in istiod in ambient multi-cluster mode when remote clusters are removed or updated.
- Fixed a goroutine leak in istiod leader election where every election cycle (leadership lost and re-acquired) leaked one goroutine until process exit.
- Fixed an issue where istiod CPU usage increased as the number of AuthorizationPolicy resources increased.
- Fixed generated Gateway Service s being rejected when two listener names sanitize to the same Service port name
value changes (2)
- Upgraded version of nftables used by Istio distroless images.
- Improved performance when fetching PeerAuthentication resources for a given workload.
조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치 같은 것들입니다.