VulnSea

skipper vulnerabilities

CVEs whose affected-version data names the skipper package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-86043High· 7.5PoC
6d ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent beca…

Midnightzalando · skipperEPSS 0.50%via NVD
CVE-2026-65838High· 8.2
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass …

Twilightzalando · skipperEPSS 0.27%via NVD
CVE-2026-54246Medium· 5.7
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/s…

Sunlitzalando · skipperEPSS 0.34%via NVD
CVE-2026-54247Medium· 4.3
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly …

Sunlitzalando · skipperEPSS 0.23%via NVD
CVE-2022-27262Critical· 9.8
4y ago

An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.

An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.

Midnightsailsjs · skipperEPSS 2.1%via NVD
skipper vulnerabilities (CVEs) · VulnSea