CVE-2026-31837

high Red Hat
CVSS v3 Base Score
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: March 10, 2026
Last Modified: March 10, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in Istio. A user of Istio could be impacted if the JSON Web Key Set (JWKS) resolver becomes unavailable or fails to fetch keys. This vulnerability can lead to the exposure of hardcoded default settings, potentially bypassing authentication mechanisms and allowing unauthorized access.

CWE

CWE-1392

Affected Products

cert-manager Operator for Red Hat OpenShiftExternalDNS OperatorOpenShift ServerlessOpenShift Service Mesh 2OpenShift Service Mesh 3Red Hat Ansible Automation Platform 2Red Hat Connectivity Link 1Red Hat OpenShift AI (RHOAI)

References