CVE-2019-14993: Istio

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding API.

Affected products

  • Istio Istio: before 1.1.13 (fixed in 1.1.13); from 1.2.0, before 1.2.4 (fixed in 1.2.4)

Published 2019-08-13. Last modified 2026-06-17.