Istio through 1.28.2 allows iptables rule injection for changing firewall behavior via the traffic.sidecar.istio.io/excludeInterfaces annotation. NOTE: the reporter's position is "this doesn't represent a security vulnerability (pod creators can already exclude sidecar injection entirely)."
History

Thu, 15 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Jan 2026 19:45:00 +0000

Type Values Removed Values Added
Description Istio through 1.28.2 allows iptables rule injection for changing firewall behavior via the traffic.sidecar.istio.io/excludeInterfaces annotation. NOTE: the reporter's position is "this doesn't represent a security vulnerability (pod creators can already exclude sidecar injection entirely)."
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-15T19:47:53.919Z

Reserved: 2026-01-15T19:18:50.553Z

Link: CVE-2026-23766

cve-icon Vulnrichment

Updated: 2026-01-15T19:47:42.641Z

cve-icon NVD

Status : Received

Published: 2026-01-15T20:16:06.057

Modified: 2026-01-15T20:16:06.057

Link: CVE-2026-23766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.