zalando has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 7.8 (high). None have a confirmed exploitation report. Most affected products: skipper (4), github.com/zalando/skipper (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 7 prev 0
Products
- skipper 4
- github.com/zalando/skipper 3
Worst active — by depth score
CVE-2026-86043High· 7.5Skipper is an HTTP router and reverse proxy for service composition53CVE-2026-50197High· 8.7Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests48CVE-2026-65838High· 8.2Skipper is an HTTP router and reverse proxy for service composition45GHSA-8qqm-fp2q-v734High· 8.2Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies45CVE-2026-54246Medium· 5.7Skipper is an HTTP router and reverse proxy for service composition31
zalando vulnerabilities
CVEs affecting zalando, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-86043High· 7.5PoCSkipper is an HTTP router and reverse proxy for service composition
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent beca…
CVE-2026-65838High· 8.2Skipper is an HTTP router and reverse proxy for service composition
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass …
CVE-2026-54246Medium· 5.7Skipper is an HTTP router and reverse proxy for service composition
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/s…
CVE-2026-54247Medium· 4.3Skipper is an HTTP router and reverse proxy for service composition
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly …
GO-2026-6019NoneSkipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper
GHSA-8qqm-fp2q-v734High· 8.2Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
CVE-2026-50197High· 8.7Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests