Research / Finding
Debug Endpoints Allow Cross-Namespace Proxy Data Access F-ISTIO-XDSDEBUG-002
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
6.9medium
Debug Endpoints Allow Cross-Namespace Proxy Data Access
Fixed in: 1.29.1, 1.28.5, 1.27.8
patched
details
Finding IDs F-ISTIO-XDSDEBUG-002 CVE CVE-2026-31838 GHSA GHSA-974c-2wxh-g4ww Status patched Fixed in 1.29.1, 1.28.5, 1.27.8 Recorded credit reported by 1seal (ISTIO-SECURITY-2026-001) CVE registry state PUBLISHED CVE state checked 23 Sep 2026 Upstream title Debug Endpoints Allow Cross-Namespace Proxy Data Access Upstream publication 10 Mar 2026 Upstream updated 6 Apr 2026 Metadata fetched 23 Sep 2026 Upstream @1seal credit @1seal: reporter (accepted) F-ISTIO-XDSDEBUG-002: Access control. Debug access crosses namespace boundaries. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-ISTIO-XDSDEBUG-002
Security area (1seal assessment): Authorization. Debug access crosses namespace boundaries. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .