1.26.8-patch5
Solo build of Istio version 1.26.8-patch5 patch release.
This release note describes what’s different between Solo builds of Istio versions 1.26.8-patch4 and 1.26.8-patch5.
Security Notice
Envoy CVEs
The following security fix was backported (see ISTIO-SECURITY-2026-004):
- CVE-2026-47774 / GHSA-22m2-hvr2-xqc8: (CVSS score 7.5, High): Fixed an HTTP/2 memory exhaustion issue where cookie header bytes were not fully accounted for during request header size validation, allowing specially crafted requests with large cookie headers to trigger excessive memory consumption and cause a denial of service.
General Changes
- Built against upstream Istio version 1.26.8, release note can be found here.
Solo Flavor Changes
No changes in this section.
FIPS Flavor Changes
No changes in this section.