VendorsRed Hatopenshift_service_meshany version
Vulnerabilities

Red Hat OpenShift Service Mesh any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-9900
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
Published 2019-04-25 · Modified
8.3EPSS 0.037
CVE-2020-1704
An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Published 2020-02-17 · Modified
7.8EPSS 0.003
CVE-2026-44495
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Published 2026-06-11 · Modified
7.7EPSS 0.010
CVE-2026-47774
Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
Published 2026-06-17 · Analyzed
7.5EPSS 0.011