Security bulletins

Use this XML feed to subscribe to Cloud Service Mesh security bulletins. Subscribe

This page lists the security bulletins for Cloud Service Mesh.

GCP-2026-045

Published: 2026-06-29

Description Severity Notes

Fixes a vulnerability where blocked QPACK decoding can cause a Denial-of-Service Attack against the HTTP/3 stack.

What should I do?

Check if your clusters are impacted

All in-cluster Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.5
  • 1.28.9-asm.4
  • 1.27.9-asm.9

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

Managed Cloud Service Mesh is not affected by this CVE.

High

GHSA-p7c7-7c47-pwch

GCP-2026-040

Published: 2026-06-23

Description Severity Notes

The fix correctly discards TLVs over the size limit.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

Moderate

CVE-2026-47692

Description Severity Notes

Fixes ext_proc issue with packed responses.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

Moderate

CVE-2026-47207

Description Severity Notes

Fixes ext_authz per route client uaf crash.

What should I do?

Check if your clusters are impacted

Only the latest 1.28 and 1.29 Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.28.9-asm.2
  • 1.27.9-asm.8

Moderate

CVE-2026-47205

Description Severity Notes

Fixes a bug where REQUESTED_SERVER_NAME may crash envoy.

What should I do?

Check if your clusters are impacted

Only the latest 1.29 Cloud Service Mesh version is impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3

High

CVE-2026-47220

Description Severity Notes

Fixed an issue when handling HTTP internal redirects for body-less requests.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

Moderate

CVE-2026-47221

Description Severity Notes

Enforce MaxInflateRatio inside the decompressor inner loop to prevent OOM from crafted payloads.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

High

CVE-2026-48044

Description Severity Notes

Cancel token client on filter destroy to avoid UAF.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

Moderate

CVE-2026-48090

Description Severity Notes

Fixes embedded NUL byte SAN validation bypass vulnerability.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

Moderate

CVE-2026-47778

Description Severity Notes

Fixes direct response grpc status issue.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

Moderate

CVE-2026-47204

Description Severity Notes

Fix sanity checking of the query name length to avoid abnormal process termination.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

Moderate

CVE-2026-48497

Description Severity Notes

Fixes TcpStatsdSync buffer overflow issue with a large status name.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

Moderate

CVE-2026-48706

Description Severity Notes

Validates HTTP/3 headers-only request and response content-length.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

High

CVE-2026-48743

Description Severity Notes

Fixes the padding oracle in OAuth2 code.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

Moderate

CVE-2026-47775

Description Severity Notes

Fixes stack overflow in destructor by limiting nesting depth.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.29.5-asm.3
  • 1.28.9-asm.2
  • 1.27.9-asm.8

If you're using Cloud Service Mesh v1.26 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

High

CVE-2026-48042

GCP-2026-035

Published: 2026-06-08

Description Severity Notes

A vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentially resulting in OOM termination of the Envoy process and denial of service.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.28.7-asm.4
  • 1.27.9-asm.5
  • 1.26.8-asm.11

If you're using Cloud Service Mesh v1.25 or earlier, your release has reached end of life and is no longer supported. This CVE fix has not been backported. Upgrade to v1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.

High

CVE-2026-47774

GCP-2026-013

Published: 2026-03-11

Description Severity Notes

Fixes multivalue header bypass in RBAC.

What should I do?

Check if your clusters are impacted

All Cloud Service Mesh versions are impacted by this CVE.

Mitigation

For in-cluster Cloud Service Mesh, upgrade your cluster to one of the following patched versions:

  • 1.28.5-asm.9
  • 1.27.8-asm.7
  • 1.26.8-asm.3

If you're using Cloud Service Mesh v1.25 or earlier, your release has reached end of life and is no longer supported. These CVE fixes have not been backported. Upgrade to version 1.26 or later.

For managed Cloud Service Mesh, follow the instructions in the MSA. All versions remain supported and your system will be automatically updated over the coming weeks.