Zalando
Products
1- 6 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38580 | Cri | 0.61 | 9.8 | 0.11 | Oct 25, 2022 | Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). | ||
| CVE-2026-23742 | Hig | 0.50 | 8.8 | 0.00 | Jan 16, 2026 | Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes… | ||
| CVE-2026-24470 | Hig | 0.46 | 8.1 | 0.00 | Jan 26, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network… | ||
| CVE-2022-34296 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2022 | In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request. | ||
| CVE-2026-65604 | Hig | 0.00 | 8.2 | 0.00 | Jul 23, 2026 | Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while… | ||
| CVE-2026-50197 | Hig | 0.00 | — | 0.00 | Jul 17, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the content-length pseudo-header,… |
- risk 0.61cvss 9.8epss 0.11
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
- risk 0.50cvss 8.8epss 0.00
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes…
- risk 0.46cvss 8.1epss 0.00
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network…
- risk 0.42cvss 7.5epss 0.01
In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
- risk 0.00cvss 8.2epss 0.00
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while…
- risk 0.00cvss —epss 0.00
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the content-length pseudo-header,…