CVE-2021-31921
Istio Control Plane (istiod) vulnerability analysis and mitigation

Overview

A remotely exploitable vulnerability was discovered in Istio versions before 1.8.6 and 1.9.x before 1.9.5, identified as CVE-2021-31921. The vulnerability allows external clients to access unexpected services in the cluster and bypass authorization checks when a gateway is configured with AUTO_PASSTHROUGH routing configuration. This security issue was disclosed on May 11, 2021, and primarily affects multi-network multi-cluster deployments (Istio Security).

Technical details

The vulnerability received a CVSS Impact Score of 10.0 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The issue specifically impacts deployments using the AUTO_PASSTHROUGH Gateway type, which is typically utilized in multi-network multi-cluster configurations. The vulnerability allows unauthorized access to cluster services by bypassing the intended authorization mechanisms (Istio Security).

Impact

When exploited, this vulnerability enables external clients to access services within the cluster that should be restricted, effectively bypassing security controls. The critical CVSS score of 10.0 indicates the potential for complete compromise of system confidentiality, integrity, and availability (Istio Security).

Exploitability

The vulnerability is remotely exploitable and requires no special privileges or user interaction to exploit. It specifically affects configurations using AUTO_PASSTHROUGH Gateway type in multi-network multi-cluster deployments (Istio Security).

Mitigation and workarounds

Users are advised to update their clusters to the latest supported versions: Istio 1.8.6 for 1.8.x users, or Istio 1.9.5 or higher for 1.9.x users. Administrators can check if they are impacted by running a kubectl command to detect AUTO_PASSTHROUGH Gateways in their cluster (Istio Security, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Istio Control Plane (istiod) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-31837HIGH8.7
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • istio-1.27
NoYesMar 10, 2026
CVE-2026-41413HIGH7.7
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • cert-manager-istio-csr-fips
NoYesMay 07, 2026
CVE-2026-31838MEDIUM6.9
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • istio-fips-1.29
NoYesMar 10, 2026
CVE-2026-39350MEDIUM5.4
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • istio-1.28
NoYesApr 15, 2026
CVE-2026-23766NONEN/A
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • cpe:2.3:a:istio:istio
NoYesJan 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management