Zalando

Skipper

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 23.07.2026 21:16:47
  • Zuletzt bearbeitet 30.07.2026 19:53:34

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to...

  • EPSS 0.43%
  • Veröffentlicht 17.07.2026 19:23:43
  • Zuletzt bearbeitet 23.07.2026 18:02:00

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the co...

  • EPSS 0.27%
  • Veröffentlicht 26.01.2026 22:23:43
  • Zuletzt bearbeitet 18.02.2026 17:39:44

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable ...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 16.01.2026 20:07:46
  • Zuletzt bearbeitet 18.02.2026 16:28:20

Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for exam...

  • EPSS 10.87%
  • Veröffentlicht 25.10.2022 17:15:55
  • Zuletzt bearbeitet 09.07.2026 01:17:40

Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

Exploit
  • EPSS 1.12%
  • Veröffentlicht 23.06.2022 17:15:18
  • Zuletzt bearbeitet 21.11.2024 07:09:14

In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.