Vulnerability Reportistio/proxyv2:1.29.2

istio/proxyv2:1.29.2-debugistio/proxyv2:1.29.2
DIGESTsha256:69ca4585993f4057861954f18be88df8268b713d114e7036bf9b185458c7a2c1

Executive Summary

Threat Score
100/100DANGEROUS
Reputation
RELIABLE

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could execute arbitrary code, bypass authorization controls, or cause denial of service, compromising the entire service mesh. The most severe vulnerabilities affect core Istio components and are exploitable without special configuration, though CVE-2026-42010 requires the non-default RSA-PSK cipher suite. Upgrading to a patched Istio version (e.g., 1.14.1 or later) is required to mitigate the critical Istio-specific flaws; no complete workarounds exist for the highest-severity issues.

Vulnerabilities

Vulnerability Log

103 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2022-31045CRITICAL9.8
istio.io/istio
v0.0.0-20260409200358-0c774325b938
fixed in 1.12.18, 1.13.5, 1.14.1
1.0%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2019-14993HIGH7.5
istio.io/istio
v0.0.0-20260409200358-0c774325b938
fixed in 1.1.13, 1.2.4
2.2%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2021-39155HIGH7.5
istio.io/istio
v0.0.0-20260409200358-0c774325b938
fixed in 1.9.8, 1.10.4, 1.11.1
1.1%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2021-39156HIGH7.5
istio.io/istio
v0.0.0-20260409200358-0c774325b938
fixed in 1.9.8, 1.10.4, 1.11.1
1.1%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2026-42013MEDIUM6.97
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42010MEDIUM6.66
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-41989MEDIUM6.38
libgcrypt20
1.10.3-2build1
fixed in 1.10.3-2ubuntu0.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42009MEDIUM6.38
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
libnghttp2-14
1.59.0-1ubuntu0.2
fixed in 1.59.0-1ubuntu0.3
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-29181MEDIUM6.38
go.opentelemetry.io/otel
v1.40.0
fixed in 1.41.0
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-3833MEDIUM6.29
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM6.29
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-29481MEDIUM6.21
libbpf1
1:1.3.0-2build2
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33845MEDIUM6.18
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42012MEDIUM6.03
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4878MEDIUM5.95
libcap2
1:2.66-5ubuntu2.2
fixed in 1:2.66-5ubuntu2.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.40.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-2236MEDIUM5.9
libgcrypt20
1.10.3-2build1
No fix yet
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-22185MEDIUM5.78
liblmdb0
0.9.31-1build1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42014MEDIUM5.61
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5260MEDIUM5.58
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4437MEDIUM5.52
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libsystemd0
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libudev1
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33846MEDIUM5.1
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33811MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5435MEDIUM5.02
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc-bin
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM4.5
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.6.1+really5.4.5-1ubuntu0.2
fixed in 5.6.1+really5.4.5-1ubuntu0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-1376MEDIUM4
libelf1t64
0.190-1.1ubuntu0.1
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4878LOW3.57
libcap2-bin
1:2.66-5ubuntu2.2
fixed in 1:2.66-5ubuntu2.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4438LOW3.4
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6429LOW3.31
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5958LOW3.21
sed
4.9-2build1
fixed in 4.9-2ubuntu0.24.04.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3832LOW3.15
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42770LOW3.01
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2025-45582LOW2.86
tar
1.35+dfsg-3build1
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-40228LOW2.8
libsystemd0
255.4-1ubuntu8.15
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
255.4-1ubuntu8.15
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45445LOW2.78
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2022-23635LOW2.7
istio.io/istio
v0.0.0-20260409200358-0c774325b938
fixed in 1.13.1, 1.12.4, 1.11.7
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-6253LOW2.7
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW2.55
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-41413LOW2.36
istio.io/istio
v0.0.0-20260409200358-0c774325b938
fixed in 0.0.0-20260410004459-189832a289c1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW2.29
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW2.29
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW2.29
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW2.29
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-1352LOW2.29
libelf1t64
0.190-1.1ubuntu0.1
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW1.99
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW1.99
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW1.99
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
login
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
passwd
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-27456NONE0
bsdextrautils
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-2219NONE0
dpkg
1.22.6ubuntu6.5
fixed in 1.22.6ubuntu6.6
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable