9 Total advisories
9 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/zalando/skipper is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 10.0
CVE-2026-50197
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
UNKNOWN
CVE-2026-24470
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName in github.com/zalando/skipper
UNKNOWN
CVE-2026-23742
Skipper is vulnerable to arbitrary code execution through lua filters in github.com/zalando/skipper
UNKNOWN
CVE-2022-34296
Query predicate bypass in Zalando Skipper in github.com/zalando/skipper
HIGH 8.8
CVE-2026-23742
Skipper is vulnerable to arbitrary code execution through lua filters
HIGH 8.1
CVE-2026-24470
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
HIGH 7.5
CVE-2022-34296
Query predicate bypass in Zalando Skipper
UNKNOWN
CVE-2022-38580
Server-side request forger via X-Skipper-Proxy in github.com/zalando/skipper
CRITICAL 9.8
CVE-2022-38580
Skipper vulnerable to SSRF via X-Skipper-Proxy
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes