{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-31838",
        "tracking": {
            "current_release_date": "2026-03-27T21:10:31.240438Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-31838",
            "initial_release_date": "2026-03-10T22:26:22.425826Z",
            "revision_history": [
                {
                    "date": "2026-03-10T22:26:22.425826Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-10T22:26:26.267033Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-10T22:38:40.012405Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (3).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-10T22:38:41.637980Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T14:39:28.167765Z",
                    "number": "5",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-11T14:39:34.673071Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T14:54:30.531232Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-12T12:16:24.791713Z",
                    "number": "8",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (5).| References created (4)."
                },
                {
                    "date": "2026-03-12T12:16:27.038242Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T00:27:50.717808Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (46).| Product Identifiers created (8).| References created (3).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-13T00:28:06.357106Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-18T19:25:21.346678Z",
                    "number": "12",
                    "summary": "CVSS created.| Products connected (3).| Product Identifiers created (3)."
                },
                {
                    "date": "2026-03-18T19:25:23.712134Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:32:42.636438Z",
                    "number": "14",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-27T09:06:35.291213Z",
                    "number": "15",
                    "summary": "Products connected (1).| References created (3)."
                }
            ],
            "status": "interim",
            "version": "15"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1441053",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:cert_manager:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Cert-manager Operator For Red Hat Openshift"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-5446213",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "ExternalDNS Operator"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1441076",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:serverless:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Serverless"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1488100",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:service_mesh:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Service Mesh 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-2942231",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:service_mesh:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Service Mesh 3"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1508257",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-2914823",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:connectivity_link:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Connectivity Link 1"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317175",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:5::server"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439279",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_ai"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1919980"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-gateway-proxy"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2652728"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-gateway-proxy-openssl30"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2652729"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-gateway-proxy-openssl32"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2551999"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cert-manager-istio-csr-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2552000"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cert-manager-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2109922"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cert-manager-operator-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441054"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetstack-cert-manager-acmesolver-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441055"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetstack-cert-manager-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "cert-manager Operator for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446214"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "external-dns-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446215"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "external-dns-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "ExternalDNS Operator"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1488101"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-cni-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1496223"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kiali-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1488102"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pilot-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1488104"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "proxyv2-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Service Mesh 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2942233"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-cni-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2942235"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-pilot-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2942236"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-proxyv2-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2942237"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-rhel9-operator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2985384"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kiali-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2985386"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kiali-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2985387"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kiali-rhel9-operator"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Service Mesh 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446216"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kn-eventing-istio-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446217"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "net-istio-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446218"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "net-istio-webhook-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446219"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "serverless-kn-operator-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446220"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "serverless-openshift-kn-rhel9-operator"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Serverless"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1906087"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-kf-notebook-controller-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5119808"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-kserve-agent-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5119810"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-kserve-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5119811"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-kserve-router-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1906088"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-controller-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3036145"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914848"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-registry-operator-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2960949"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-registry-operator-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2960950"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-registry-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1906089"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-notebook-controller-rhel8"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914831"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhcl-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914832"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhcl-rhel9-operator"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Connectivity Link 1"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/envoy proxy",
                                "product": {
                                    "name": "vers:unknown/envoy proxy",
                                    "product_id": "CSAFPID-5810304",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:google:cloud_platform:envoy_proxy"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/istio",
                                "product": {
                                    "name": "vers:unknown/istio",
                                    "product_id": "CSAFPID-5810308",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:google:cloud_platform:istio"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/service mesh <1.26.8-asm.3",
                                "product": {
                                    "name": "vers:unknown/service mesh <1.26.8-asm.3",
                                    "product_id": "CSAFPID-5810305"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/service mesh <1.27.8-asm.7",
                                "product": {
                                    "name": "vers:unknown/service mesh <1.27.8-asm.7",
                                    "product_id": "CSAFPID-5810307"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/service mesh <1.28.5-asm.9",
                                "product": {
                                    "name": "vers:unknown/service mesh <1.28.5-asm.9",
                                    "product_id": "CSAFPID-5810306"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Cloud Platform"
                    }
                ],
                "category": "vendor",
                "name": "Google"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.27.8",
                                "product": {
                                    "name": "vers:unknown/<1.27.8",
                                    "product_id": "CSAFPID-5779787",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.28.0-alpha.0|<1.28.5",
                                "product": {
                                    "name": "vers:unknown/>=1.28.0-alpha.0|<1.28.5",
                                    "product_id": "CSAFPID-5779786"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.28.0|<1.28.5",
                                "product": {
                                    "name": "vers:unknown/>=1.28.0|<1.28.5",
                                    "product_id": "CSAFPID-5845003",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.29.0-alpha.0|<1.29.1",
                                "product": {
                                    "name": "vers:unknown/>=1.29.0-alpha.0|<1.29.1",
                                    "product_id": "CSAFPID-5779785"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.29.0|<1.29.1",
                                "product": {
                                    "name": "vers:unknown/>=1.29.0|<1.29.1",
                                    "product_id": "CSAFPID-5845004",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Istio"
                    }
                ],
                "category": "vendor",
                "name": "Istio"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-31838",
            "cwe": {
                "id": "CWE-863",
                "name": "Incorrect Authorization"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain multiple values. An attacker could craft requests with multiple header values in a way that causes Envoy to evaluate the header differently than intended, potentially bypassing authorization checks. This may allow unauthorized requests to reach protected services when policies depend on such header-based matching conditions. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-31838"
                },
                {
                    "category": "description",
                    "text": "Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain multiple values. An attacker could craft requests with multiple header values in a way that causes Envoy to evaluate the header differently than intended, potentially bypassing authorization checks. This may allow unauthorized requests to reach protected services when policies depend on such header-based matching conditions. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-31838"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Istio. This vulnerability in Envoy's Role-Based Access Control (RBAC) header matching could allow an attacker to bypass authorization policies. By crafting requests with multiple header values, an attacker could cause Envoy to misinterpret the header, leading to unauthorized access to protected services.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-31838"
                },
                {
                    "category": "other",
                    "text": "0.00039",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "6.9",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.9",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is cvss data available from source Redhat",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5779785",
                    "CSAFPID-5779786",
                    "CSAFPID-5779787",
                    "CSAFPID-5810304",
                    "CSAFPID-5810305",
                    "CSAFPID-5810306",
                    "CSAFPID-5810307",
                    "CSAFPID-5810308",
                    "CSAFPID-1439279",
                    "CSAFPID-1441053",
                    "CSAFPID-1441054",
                    "CSAFPID-1441055",
                    "CSAFPID-1441076",
                    "CSAFPID-1488100",
                    "CSAFPID-1488101",
                    "CSAFPID-1488102",
                    "CSAFPID-1488104",
                    "CSAFPID-1496223",
                    "CSAFPID-1906087",
                    "CSAFPID-1906088",
                    "CSAFPID-1906089",
                    "CSAFPID-2109922",
                    "CSAFPID-2551999",
                    "CSAFPID-2552000",
                    "CSAFPID-2914823",
                    "CSAFPID-2914831",
                    "CSAFPID-2914832",
                    "CSAFPID-2914848",
                    "CSAFPID-2942231",
                    "CSAFPID-2942233",
                    "CSAFPID-2942235",
                    "CSAFPID-2942236",
                    "CSAFPID-2942237",
                    "CSAFPID-2960949",
                    "CSAFPID-2960950",
                    "CSAFPID-2985384",
                    "CSAFPID-2985386",
                    "CSAFPID-2985387",
                    "CSAFPID-3036145",
                    "CSAFPID-5119808",
                    "CSAFPID-5119810",
                    "CSAFPID-5119811",
                    "CSAFPID-5446213",
                    "CSAFPID-5446214",
                    "CSAFPID-5446215",
                    "CSAFPID-5446216",
                    "CSAFPID-5446217",
                    "CSAFPID-5446218",
                    "CSAFPID-5446219",
                    "CSAFPID-5446220",
                    "CSAFPID-5845003",
                    "CSAFPID-5845004",
                    "CSAFPID-1317175"
                ],
                "known_not_affected": [
                    "CSAFPID-1508257",
                    "CSAFPID-1919980",
                    "CSAFPID-2652728",
                    "CSAFPID-2652729"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31838"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-31838"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-31838"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/31xxx/CVE-2026-31838.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-31838"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0704.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-31838"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-31838.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; redhat",
                    "url": "https://github.com/istio/istio/security/advisories/GHSA-974c-2wxh-g4ww"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0704.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0704"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://docs.cloud.google.com/support/bulletins#gcp-2026-013"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-013"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-31838"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31838"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://access.redhat.com/errata/RHSA-2026:5952"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://access.redhat.com/errata/RHSA-2026:5950"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://access.redhat.com/errata/RHSA-2026:5948"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1317175",
                        "CSAFPID-1439279",
                        "CSAFPID-1441053",
                        "CSAFPID-1441054",
                        "CSAFPID-1441055",
                        "CSAFPID-1441076",
                        "CSAFPID-1488100",
                        "CSAFPID-1488101",
                        "CSAFPID-1488102",
                        "CSAFPID-1488104",
                        "CSAFPID-1496223",
                        "CSAFPID-1906087",
                        "CSAFPID-1906088",
                        "CSAFPID-1906089",
                        "CSAFPID-2109922",
                        "CSAFPID-2551999",
                        "CSAFPID-2552000",
                        "CSAFPID-2914823",
                        "CSAFPID-2914831",
                        "CSAFPID-2914832",
                        "CSAFPID-2914848",
                        "CSAFPID-2942231",
                        "CSAFPID-2942233",
                        "CSAFPID-2942235",
                        "CSAFPID-2942236",
                        "CSAFPID-2942237",
                        "CSAFPID-2960949",
                        "CSAFPID-2960950",
                        "CSAFPID-2985384",
                        "CSAFPID-2985386",
                        "CSAFPID-2985387",
                        "CSAFPID-3036145",
                        "CSAFPID-5119808",
                        "CSAFPID-5119810",
                        "CSAFPID-5119811",
                        "CSAFPID-5446213",
                        "CSAFPID-5446214",
                        "CSAFPID-5446215",
                        "CSAFPID-5446216",
                        "CSAFPID-5446217",
                        "CSAFPID-5446218",
                        "CSAFPID-5446219",
                        "CSAFPID-5446220",
                        "CSAFPID-5779785",
                        "CSAFPID-5779786",
                        "CSAFPID-5779787",
                        "CSAFPID-5810304",
                        "CSAFPID-5810305",
                        "CSAFPID-5810306",
                        "CSAFPID-5810307",
                        "CSAFPID-5810308",
                        "CSAFPID-5845003",
                        "CSAFPID-5845004"
                    ]
                }
            ],
            "title": "CVE-2026-31838"
        }
    ]
}