An attacker-controlled OCI registry redirects the Wasm fetcher to internal/metadata endpoints because pkg/wasm/imagefetcher.go trusts the registry-returned Location header without re-applying SSRF guards.
| Vendor | Product | Versions |
|---|---|---|
| istio | wasm oci image fetcher | 1.29.1, 1.29.2, 1.29.3, 1.29.4, 1.29.5, 1.30.0, 1.30.1, 1.30.2, master (2b217d65b4) |
Updated description with additional technical details about the vulnerability's exploitation method.
Updated exploit availability to true, marked as actively exploited, and added new tag '0-day'.
Initial creation