VYPR
Vendor

Zalando

Products
2
CVEs
10
Across products
10
Status
Private

Products

2

Recent CVEs

10
  • CVE-2022-38580CriOct 25, 2022
    risk 0.61cvss 9.8epss 0.12

    Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

  • CVE-2026-23742HigJan 16, 2026
    risk 0.50cvss 8.8epss 0.01

    Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes…

  • CVE-2026-65838HigSep 14, 2026
    risk 0.46cvss 8.2epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because…

  • CVE-2026-24470HigJan 26, 2026
    risk 0.46cvss 8.1epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network…

  • CVE-2026-86043HigSep 16, 2026
    risk 0.42cvss 7.5epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent because the input.truncated_body signal is…

  • CVE-2022-34296HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.

  • CVE-2026-54246MedSep 14, 2026
    risk 0.30cvss 5.7epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/shards, and /swarm/valkey/shards. The…

  • CVE-2026-54247MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size…

  • CVE-2026-65604HigJul 23, 2026
    risk 0.00cvss 8.2epss 0.00

    Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while…

  • CVE-2026-50197HigJul 17, 2026
    risk 0.00cvss —epss 0.01

    Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the content-length pseudo-header,…