17 Total advisories
17 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/zalando/skipper is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.2
CVE-2026-65838
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
HIGH 7.5
CVE-2026-86043
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
UNKNOWN
CVE-2026-65838
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper
MEDIUM 4.3
CVE-2026-54247
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS
MEDIUM 5.7
CVE-2026-54246
Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication
UNKNOWN
CVE-2026-54247
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS in github.com/zalando/skipper
UNKNOWN
CVE-2026-54246
Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication in github.com/zalando/skipper
CRITICAL 10.0
CVE-2026-50197
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
UNKNOWN
CVE-2026-50197
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests in github.com/zalando/skipper
UNKNOWN
CVE-2026-24470
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName in github.com/zalando/skipper
UNKNOWN
CVE-2026-23742
Skipper is vulnerable to arbitrary code execution through lua filters in github.com/zalando/skipper
UNKNOWN
CVE-2022-34296
Query predicate bypass in Zalando Skipper in github.com/zalando/skipper
HIGH 8.8
CVE-2026-23742
Skipper is vulnerable to arbitrary code execution through lua filters
HIGH 8.1
CVE-2026-24470
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
HIGH 7.5
CVE-2022-34296
Query predicate bypass in Zalando Skipper
UNKNOWN
CVE-2022-38580
Server-side request forger via X-Skipper-Proxy in github.com/zalando/skipper
CRITICAL 9.8
CVE-2022-38580
Skipper vulnerable to SSRF via X-Skipper-Proxy
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes