Back to VulnFeed / CVE-2026-41413
root@hackertop:~/vulnfeed/CVE-2026-41413#
CVE-2026-41413 MEDIUM SSRF ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

Istio up to 1.28.5/1.29.1 HTTP GET Request server-side request forgery

Istio 14d ago Impact pending confirmation
LIFECYCLE
5.5 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability was found in Istio up to 1.28.5/1.29.1 and classified as critical. This issue affects an unknown part of the component HTTP GET Request Handler. Upgrading to version 1.28.6 or 1.29.2 eliminates this vulnerability.
Root Cause Analysis
Using CWE to declare the problem leads to CWE-918. The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Impact: Impacted is confidentiality, integrity, and availability.

Countermeasure: Upgrading to version 1.28.6 or 1.29.2 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-41413 · CVSS 5.5 · Active Threat