RATATOSKRATATOSK
로그인

Istio

1.29.7Networking & Messaging
2026년 8월 27일

ACTION 3CHECK 17OTHER 13

여러 `Envoy` 및 `Istio` 보안 취약점을 수정하고, 인증과 기본 동작을 변경한 보안 중심 유지보수 릴리스입니다. 정확성과 성능에 관한 수정도 포함되어 있습니다.

조치 필요 (3)

  • security매개변수가 포함된 경로 구간의 URL 정규화 수정

    매개변수가 포함된 점 및 두 점 경로 구간의 URL 정규화를 수정했습니다. CVE-2026-73551에 해당합니다.

  • security구간별 매개변수 경로 일치 수정

    구간별 매개변수가 있는 경로 일치 처리를 수정했습니다. CVE-2026-73511에 해당합니다.

  • security일반 HTTP 업그레이드의 사용자 간 응답 오염 수정

    일반 HTTP 업그레이드에서 사용자 간 응답 오염이 발생하던 문제를 수정했습니다. CVE-2026-73548에 해당합니다.

영향 확인 (17)

  • securityHTTP/2 트레일러 처리 중 힙 해제 후 사용 수정

    HTTP/2를 사용하는 경우에 해당합니다.

    HTTP/2 트레일러가 END_STREAM 플래그 없이 들어올 때 oghttp2에서 발생하던 힙 해제 후 사용 문제를 수정했습니다. CVE-2026-73513에 해당합니다.

  • security음수 일치 RBAC 정책의 safe_regex 검사 수정

    음수가 일치하는 RBAC 정책을 사용하는 경우에 해당합니다.

    음수가 일치하는 RBAC 정책에서 safe_regexUTF-8이 아닌 헤더 바이트를 허용하던 문제를 수정했습니다. CVE-2026-73552에 해당합니다.

  • securityQUIC HTTP 데이터그램 처리기의 해제 후 사용 수정

    QUIC HTTP 데이터그램 처리기를 사용하는 경우에 해당합니다.

    QUIC HTTP 데이터그램 처리기에서 발생하던 해제 후 사용 문제를 수정했습니다. CVE-2026-73512에 해당합니다.

  • security:path 없는 CONNECT 요청의 ext_authz 비정상 종료 수정

    ext_authz를 사용하는 경우에 해당합니다.

    :path 헤더가 없는 CONNECT 요청을 처리할 때 ext_authz가 비정상 종료하던 문제를 수정했습니다. CVE-2026-73547에 해당합니다.

  • securityHTTP/3의 범위 지정 IPv6 주소 처리 수정

    HTTP/3를 사용하는 경우에 해당합니다.

    HTTP/3에서 범위가 지정된 IPv6 클라이언트 주소를 처리할 때 비정상 종료하던 문제를 수정했습니다. CVE-2026-73549에 해당합니다.

  • securityext_authz 원시 HTTP 클라이언트의 해제 후 사용 수정

    ext_authz 원시 HTTP 클라이언트를 사용하는 경우에 해당합니다.

    ext_authz 원시 HTTP 클라이언트에서 발생하던 해제 후 사용 문제를 수정했습니다. CVE-2026-50572에 해당합니다.

  • securityHTML stats interface의 저장형 사이트 간 스크립팅 수정

    HTML stats interface를 사용하는 경우에 해당합니다.

    HTML stats interface에 저장형 사이트 간 스크립팅 취약점이 있던 문제를 수정했습니다. CVE-2026-73546에 해당합니다.

  • securityHTTP/3 연결 풀 선택 중 널 포인터 역참조 수정

    HTTP/3를 사용하는 경우에 해당합니다.

    ALPN 기반 HTTP/3 연결 풀을 선택하는 과정에서 널 포인터를 역참조하던 문제를 수정했습니다. CVE-2026-48521에 해당합니다.

  • security중복 Host 헤더로 인한 HTTP/2 메모리 고갈 수정

    HTTP/2를 사용하는 경우에 해당합니다.

    중복된 Host 헤더를 버리는 과정에서 HTTP/2 메모리가 고갈될 수 있던 문제를 수정했습니다. CVE-2026-73550에 해당합니다.

  • securityignore_path_parameters_in_path_matching을 통한 RBAC 우회 수정

    ignore_path_parameters_in_path_matching을 설정한 경우에 해당합니다.

    ignore_path_parameters_in_path_matching 설정을 이용해 RBAC를 우회할 수 있던 문제를 수정했습니다. CVE-2026-73553에 해당합니다.

  • securityBackendTLSPolicy의 확인되지 않은 CA reference 처리 수정

    BackendTLSPolicy를 설정하고 sidecar 프록시를 실행하면서 CA reference를 지정하지 않은 경우에 해당합니다.

    CA reference를 확인하지 못한 sidecar 프록시에서 BackendTLSPolicy가 평문 통신으로 허용되던 문제를 수정했습니다. GHSA-qm8v-g4f9-qhjx에 해당합니다.

  • securityEnvoyFilter 일치 표현식 길이 제한

    일치 표현식이 있는 EnvoyFilter를 설정한 경우에 해당합니다.

    EnvoyFilter의 일치 표현식 길이를 1024자로 제한했습니다.

  • securityingress gateways 인증 정책 적용 수정

    ingress gateways를 실행하는 경우에 해당합니다.

    ingress gateways에서 인증 정책이 적용되지 않던 문제를 수정했습니다.

  • securityGateway APIResolvedRefs 정보 노출 수정

    Gateway API를 사용하는 경우에 해당합니다.

    권한 부여가 참조를 허용하지 않아도 리스너의 ResolvedRefs 상태에서 참조된 Secret 또는 ConfigMap의 존재 여부가 드러날 수 있던 문제를 수정했습니다.

  • securityistiod jwksUri 요청의 SSRF 수정

    istiod를 실행하고 jwksUri를 설정한 경우에 해당합니다.

    istiodRequestAuthentication에서 jwksUri를 가져올 때 발생하던 SSRF 허점을 수정했습니다.

  • securityENABLE_XDS_API_GENERATOR_AUTH 기본값 변경

    ENABLE_XDS_API_GENERATOR_AUTH를 설정하지 않은 경우에 해당합니다.

    ENABLE_XDS_API_GENERATOR_AUTH의 기본값을 true로 변경했습니다. 호환성을 위해 필요한 경우 ENABLE_XDS_API_GENERATOR_AUTH=false로 끌 수 있습니다.

  • security사이드카 및 게이트웨이 주입 템플릿의 주석 처리 수정

    proxyImage, bootstrapOverride, logLevel, componentLogLevel, agentLogLevel 가운데 하나라도 설정한 경우에 해당합니다.

    proxyImage, bootstrapOverride, logLevel, componentLogLevel, agentLogLevel이 사이드카 및 게이트웨이 주입 템플릿에 출력 이스케이프 없이 삽입되던 문제를 수정했습니다.

그 외 기록된 변경 13건 전체fixes 11 · value changes 2

fixes (11)

  • Fixed a race condition on istiod startup where the readiness probe could report ready before the dedicated injection and validation webhook server ( --httpsAddr , default :15017 ) was accepting connections
  • Fixed an issue where gateway proxy Deployment resources could permanently fail to be created during istiod startup.
  • Fixed an issue where istio-cni considered hostNetwork pods eligible for ambient enrollment.
  • Fixed a file descriptor leak in the istio-cni node agent
  • Fixed a bug where the istio-cni node agent could pair an ambient pod with another pod’s network namespace
  • Fixed an issue where istiod permanently retained a copy of every workload resource name
  • Fixed a bug where a ztunnel reconnect (such as the periodic connection recycle from keepaliveMaxServerConnectionAge ) triggered a full workload (WDS) push.
  • Fixed goroutine and memory leaks in istiod in ambient multi-cluster mode when remote clusters are removed or updated.
  • Fixed a goroutine leak in istiod leader election where every election cycle (leadership lost and re-acquired) leaked one goroutine until process exit.
  • Fixed an issue where istiod CPU usage increased as the number of AuthorizationPolicy resources increased.
  • Fixed generated Gateway Service s being rejected when two listener names sanitize to the same Service port name

value changes (2)

  • Upgraded version of nftables used by Istio distroless images.
  • Improved performance when fetching PeerAuthentication resources for a given workload.
Istio 스택에 추가

조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치 같은 것들입니다.

스택에 추가