GHSA-9gcg-w975-3rjh

Suggest an improvement
Source
https://github.com/advisories/GHSA-9gcg-w975-3rjh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-9gcg-w975-3rjh/GHSA-9gcg-w975-3rjh.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9gcg-w975-3rjh
Aliases
Downstream
CGA (6)
MINI (12)
Published
2026-04-16T20:44:46Z
Modified
2026-07-17T21:04:27Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots
Details

Impact

The serviceAccounts and notServiceAccounts fields in AuthorizationPolicy incorrectly interpret dots (.) as a regular expression matcher. Because . is a valid character in a service account name, an AuthorizationPolicy ALLOW rule targeting SA e.g. cert-manager.io also matches cert-manager-io, cert-managerXio, etc. A DENY rule targeting the same name fails to block those variants.

Patches

Fixes are available in 1.29.2, 1.28.6, and 1.27.9

Workarounds

None

Database specific
{
    "cwe_ids": [
        "CWE-185"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-16T20:44:46Z",
    "nvd_published_at": "2026-04-15T23:16:09Z",
    "severity": "MODERATE"
}
References

Affected packages

Go / istio.io/istio

Package

Name
istio.io/istio
View open source insights on deps.dev
Purl
pkg:golang/istio.io/istio

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-20241024090207-0bf27d49ba4b
Fixed
0.0.0-20260403004500-692e460c342d

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-9gcg-w975-3rjh/GHSA-9gcg-w975-3rjh.json"