CVE-2022-31045

    Dashboard / Vulnerabilities / CVE-2022-31045

    CVE-2022-31045

    Published: 9 Jun 2022Last Modified: 12 Aug 2026

    Summary: Ill-formed headers may lead to unexpected behavior in Istio

    Details: Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an Istio ingress Gateway exposed to external traffic. This vulnerability has been resolved in versions 1.12.8, 1.13.5, and 1.14.1. Users are advised to upgrade. There are no known workarounds for this issue.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 75ee7514615d3a642a7eabaa0ad7c22cea1a1ed0

    Affected versions

    1.14.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-31045 | CVE-DB