Security: zalando/skipper
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Token introspection client credentials are shared per issuer, so routes introspect as each otherGHSA-v9vv-w45w-rppw published
Aug 18, 2026 by szuecsModerate -
OAuth2 grant and OIDC login flow state is not bound to the user agent, allowing login CSRFGHSA-7g9f-57qp-jhgx published
Aug 18, 2026 by szuecsModerate -
The OPA authorization filter sets policy headers with Header.Add rather than overrideGHSA-wvv5-jv5r-xq52 published
Sep 2, 2026 by szuecsCritical -
OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734 / CVE-2026-50197)GHSA-5gpm-rgj3-9q76 published
Jul 22, 2026 by szuecsHigh -
Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policiesGHSA-8qqm-fp2q-v734 published
Jul 9, 2026 by szuecsHigh -
Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoSGHSA-cwxq-rc9x-2jvv published
Jun 5, 2026 by szuecsModerate -
routesrv-no-auth: All routesrv API Endpoints Lack AuthenticationGHSA-5587-2x54-jj6h published
Jun 24, 2026 by szuecsModerate -
opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding: chunked / HTTP/2 requestsGHSA-659f-rgp5-w4wf published
Jun 1, 2026 by szuecsHigh -
dataclient/kubernetes ExternalName SSRF Leading to Internal Service ExposureGHSA-mxxc-p822-2hx9 published
Jan 26, 2026 by szuecsHigh -
skipper arbitrary code execution through lua filtersGHSA-cc8m-98fm-rc9g published
Jan 16, 2026 by szuecsHigh