Zalando
Products
2- 10 CVEs
- 0 CVEs
Recent CVEs
10| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38580 | Cri | 0.61 | 9.8 | 0.12 | Oct 25, 2022 | Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). | ||
| CVE-2026-23742 | Hig | 0.50 | 8.8 | 0.01 | Jan 16, 2026 | Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes… | ||
| CVE-2026-65838 | Hig | 0.46 | 8.2 | 0.00 | Sep 14, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because… | ||
| CVE-2026-24470 | Hig | 0.46 | 8.1 | 0.00 | Jan 26, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network… | ||
| CVE-2026-86043 | Hig | 0.42 | 7.5 | 0.00 | Sep 16, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent because the input.truncated_body signal is… | ||
| CVE-2022-34296 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2022 | In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request. | ||
| CVE-2026-54246 | Med | 0.30 | 5.7 | 0.00 | Sep 14, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/shards, and /swarm/valkey/shards. The… | ||
| CVE-2026-54247 | Med | 0.21 | 4.3 | 0.00 | Sep 14, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size… | ||
| CVE-2026-65604 | Hig | 0.00 | 8.2 | 0.00 | Jul 23, 2026 | Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while… | ||
| CVE-2026-50197 | Hig | 0.00 | — | 0.01 | Jul 17, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the content-length pseudo-header,… |
- risk 0.61cvss 9.8epss 0.12
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
- risk 0.50cvss 8.8epss 0.01
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes…
- risk 0.46cvss 8.2epss 0.00
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because…
- risk 0.46cvss 8.1epss 0.00
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network…
- risk 0.42cvss 7.5epss 0.00
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent because the input.truncated_body signal is…
- risk 0.42cvss 7.5epss 0.01
In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
- risk 0.30cvss 5.7epss 0.00
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/shards, and /swarm/valkey/shards. The…
- risk 0.21cvss 4.3epss 0.00
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size…
- risk 0.00cvss 8.2epss 0.00
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while…
- risk 0.00cvss —epss 0.01
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the content-length pseudo-header,…