VYPR
Vendor

Zalando

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2022-38580CriOct 25, 2022
    risk 0.61cvss 9.8epss 0.11

    Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

  • CVE-2026-23742HigJan 16, 2026
    risk 0.50cvss 8.8epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes…

  • CVE-2026-24470HigJan 26, 2026
    risk 0.46cvss 8.1epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network…

  • CVE-2022-34296HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.

  • CVE-2026-65604HigJul 23, 2026
    risk 0.00cvss 8.2epss 0.00

    Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while…

  • CVE-2026-50197HigJul 17, 2026
    risk 0.00cvss epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the content-length pseudo-header,…