CVE-2026-86043
- EPSS 0.5%
- Veröffentlicht 16.09.2026 18:51:20
- Zuletzt bearbeitet 16.09.2026 20:17:36
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent because the input...
CVE-2026-54247
- EPSS 0.23%
- Veröffentlicht 14.09.2026 20:04:06
- Zuletzt bearbeitet 16.09.2026 17:17:20
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll...
CVE-2026-54246
- EPSS 0.34%
- Veröffentlicht 14.09.2026 20:03:14
- Zuletzt bearbeitet 16.09.2026 13:42:48
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/shards, and /s...
CVE-2026-65838
- EPSS 0.27%
- Veröffentlicht 14.09.2026 20:01:27
- Zuletzt bearbeitet 16.09.2026 13:42:48
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-pre...
CVE-2026-65604
- EPSS 0.29%
- Veröffentlicht 23.07.2026 21:16:47
- Zuletzt bearbeitet 30.07.2026 19:53:34
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to...
CVE-2026-50197
- EPSS 0.43%
- Veröffentlicht 17.07.2026 19:23:43
- Zuletzt bearbeitet 23.07.2026 18:02:00
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the co...
CVE-2026-24470
- EPSS 0.27%
- Veröffentlicht 26.01.2026 22:23:43
- Zuletzt bearbeitet 18.02.2026 17:39:44
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable ...
CVE-2026-23742
- EPSS 0.48%
- Veröffentlicht 16.01.2026 20:07:46
- Zuletzt bearbeitet 18.02.2026 16:28:20
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for exam...
CVE-2022-38580
- EPSS 10.87%
- Veröffentlicht 25.10.2022 17:15:55
- Zuletzt bearbeitet 09.07.2026 01:17:40
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
CVE-2022-34296
- EPSS 1.12%
- Veröffentlicht 23.06.2022 17:15:18
- Zuletzt bearbeitet 21.11.2024 07:09:14
In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.