VulnSea

zalando has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 7.8 (high). None have a confirmed exploitation report. Most affected products: skipper (4), github.com/zalando/skipper (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
7 prev 0

Products

  • skipper 4
  • github.com/zalando/skipper 3
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

zalando vulnerabilities

CVEs affecting zalando, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-86043High· 7.5PoC
6d ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent beca…

Midnightzalando · skipperEPSS 0.50%via NVD
CVE-2026-65838High· 8.2
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass …

Twilightzalando · skipperEPSS 0.27%via NVD
CVE-2026-54246Medium· 5.7
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/s…

Sunlitzalando · skipperEPSS 0.34%via NVD
CVE-2026-54247Medium· 4.3
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly …

Sunlitzalando · skipperEPSS 0.23%via NVD
GO-2026-6019None
2mo ago

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper

Sunlitzalando · github.com/zalando/skippervia OSV
GHSA-8qqm-fp2q-v734High· 8.2
2mo ago

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

Twilightzalando · github.com/zalando/skippervia GHSA
CVE-2026-50197High· 8.7
2mo ago

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

Twilightzalando · github.com/zalando/skipperEPSS 0.55%via GHSA
zalando vulnerabilities (CVEs) · VulnSea