Vulnerabilities > Istio > Istio > 1.15.0

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 Resource Exhaustion vulnerability in multiple products
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
2022-11-10 CVE-2022-39388 Incorrect Authorization vulnerability in Istio 1.15.0/1.15.1/1.15.2
Istio is an open platform to connect, manage, and secure microservices.
low complexity
istio CWE-863
3.5
2022-10-13 CVE-2022-39278 Resource Exhaustion vulnerability in Istio
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection.
network
low complexity
istio CWE-400
7.5