Skipper
Zalando · 10 CVEs
Skipper: OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix CVE-2026-50197)
Sep 16, 2026
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS
Sep 14, 2026
Skipper routesrv-no-auth: All routesrv API Endpoints Lack Authentication
Sep 14, 2026
Skipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego p…
Sep 14, 2026
Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass
Jul 23, 2026
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding: chunked / HTTP/2 requests
Jul 17, 2026
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
Jan 26, 2026
Skipper arbitrary code execution through lua filters
Jan 16, 2026
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
Oct 24, 2022
In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
Jun 22, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-86043 | Skipper: OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix CVE-2026-50197) | HIGH | 0.45% | Sep 16, 2026 |
| CVE-2026-54247 | Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS | MEDIUM | 0.30% | Sep 14, 2026 |
| CVE-2026-54246 | Skipper routesrv-no-auth: All routesrv API Endpoints Lack Authentication | MEDIUM | 0.34% | Sep 14, 2026 |
| CVE-2026-65838 | Skipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego policies fail OPEN while the full payload… | HIGH | 0.46% | Sep 14, 2026 |
| CVE-2026-65604 | Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass | HIGH | 0.39% | Jul 23, 2026 |
| CVE-2026-50197 | Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding: chunked / HTTP/2 requests | HIGH | 0.55% | Jul 17, 2026 |
| CVE-2026-24470 | Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName | HIGH | 0.31% | Jan 26, 2026 |
| CVE-2026-23742 | Skipper arbitrary code execution through lua filters | HIGH | 0.52% | Jan 16, 2026 |
| CVE-2022-38580 | Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). | CRITICAL | 11.96% | Oct 24, 2022 |
| CVE-2022-34296 | In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request. | HIGH | 1.15% | Jun 22, 2022 |
Showing 1 to 10 of 10 CVEs