CVE-2026-39350 | Istio up to 1.27.8/1.28.5/1.29.1 notServiceAccounts incorrect regex (GHSA-9gcg-w975-3rjh)
A vulnerability labeled as critical has been found in Istio up to 1.27.8/1.28.5/1.29.1. Affected by this issue is some unknown functionality. The manipulation of the argument notServiceAccounts results in incorrect regular expression.
This vulnerability is cataloged as CVE-2026-39350. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.