Istio · Istio · CVE-2026-23766
**Name of the Vulnerable Software and Affected Versions**
Istio versions through 1.28.2
**Description**
Istio versions through 1.28.2 permit the injection of iptables rules, potentially altering firewall behavior. This is achieved through the `traffic.sidecar.istio.io/excludeInterfaces` annotation. The reporter notes that this may not represent a security issue, as pod creators can already prevent sidecar injection.
**Recommendations**
Versions prior to 1.28.3 are affected.