github.com/zalando/skipper
Package skipper provides an HTTP routing library with flexible configuration as well as a runtime update of the routing rules.
Security Advisories for github.com/zalando/skipper in go
High
about 1 month ago
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
go
github.com/zalando/skipper
Moderate
about 1 month ago
Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication
go
github.com/zalando/skipper
Moderate
about 1 month ago
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS
go
github.com/zalando/skipper
High
about 1 month ago
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
go
github.com/zalando/skipper
High
7 months ago
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
go
github.com/zalando/skipper
High
7 months ago
Skipper is vulnerable to arbitrary code execution through lua filters
go
github.com/zalando/skipper
Critical
almost 4 years ago
Skipper vulnerable to SSRF via X-Skipper-Proxy
go
github.com/zalando/skipper