CVE-2019-14993: Istio
High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding API.
Affected products
- Istio Istio: before 1.1.13 (fixed in 1.1.13); from 1.2.0, before 1.2.4 (fixed in 1.2.4)
Published 2019-08-13. Last modified 2026-06-17.