go

github.com/zalando/skipper

View on go registry
17 Total advisories
17 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/zalando/skipper is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.2
Go

CVE-2026-65838

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

HIGH 7.5
Go

CVE-2026-86043

Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)

UNKNOWN
Go

CVE-2026-65838

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper

MEDIUM 4.3
Go

CVE-2026-54247

Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS

MEDIUM 5.7
Go

CVE-2026-54246

Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication

UNKNOWN
Go

CVE-2026-54247

Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS in github.com/zalando/skipper

UNKNOWN
Go

CVE-2026-54246

Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication in github.com/zalando/skipper

CRITICAL 10.0
Go

CVE-2026-50197

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

UNKNOWN
Go

CVE-2026-50197

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests in github.com/zalando/skipper

UNKNOWN
Go

CVE-2026-24470

Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName in github.com/zalando/skipper

UNKNOWN
Go

CVE-2026-23742

Skipper is vulnerable to arbitrary code execution through lua filters in github.com/zalando/skipper

UNKNOWN
Go

CVE-2022-34296

Query predicate bypass in Zalando Skipper in github.com/zalando/skipper

HIGH 8.8
Go

CVE-2026-23742

Skipper is vulnerable to arbitrary code execution through lua filters

HIGH 8.1
Go

CVE-2026-24470

Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName

HIGH 7.5
Go

CVE-2022-34296

Query predicate bypass in Zalando Skipper

UNKNOWN
Go

CVE-2022-38580

Server-side request forger via X-Skipper-Proxy in github.com/zalando/skipper

CRITICAL 9.8
Go

CVE-2022-38580

Skipper vulnerable to SSRF via X-Skipper-Proxy

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes