Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.45% | — | SkipperAI | 16/9/2026 | 16/9/2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent because the input.truncated_body signal is derived from Content-Length rather than the… | |
| Aplazada | Alta (8.2) | 0.46% | — | SkipperAIOpenpolicyagent Open Policy AgentAI | 14/9/2026 | 16/9/2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with… | |
| Aplazada | Media (4.3) | 0.30% | — | SkipperAI | 14/9/2026 | 16/9/2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size limit. An attacker with in-cluster network… | |
| Aplazada | Media (5.7) | 0.34% | — | SkipperAI | 14/9/2026 | 16/9/2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/shards, and /swarm/valkey/shards. The handlers registered in routesrv/routesrv.go,… | |
| Aplazada | Alta (8.8) | 0.39% | — | Zalando SkipperAIOpenpolicyagent OPAAI | 23/7/2026 | 30/7/2026 | Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty… | |
| Aplazada | Alta (7.8) | 0.55% | — | Zalando SkipperAI | 17/7/2026 | 23/7/2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the content-length pseudo-header, because the opaAuthorizeRequestWithBody… | |
| Analizada | Alta (8.1) | 0.31% | — | Zalando Skipper | 26/1/2026 | 17/6/2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network access to reach internal services.… | |
| Analizada | Alta (8.8) | 0.52% | — | Zalando Skipper | 16/1/2026 | 17/6/2026 | Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes Ingress resource. The configuration inline… | |
| Aplazada | Alta (8.8) | 18% | — | Vmware Cloud Data FlowAIVmware SkipperAI | 19/6/2024 | 17/6/2026 | Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted… | |
| Modificada | Crítica (9.8) | 12% | — | Zalando Skipper | 25/10/2022 | 9/7/2026 | Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). | |
| Modificada | Alta (7.5) | 1.1% | — | Zalando Skipper | 23/6/2022 | 17/6/2026 | In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request. | |
| Modificada | Crítica (9.8) | 2.1% | — | Sailsjs Skipper | 12/4/2022 | 9/7/2026 | An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (5) | 3.5% | — | Nadeo Game EngineNadeo TrackmaniaNadeo Virtual Skipper | 8/2/2004 | 16/6/2026 | Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields. |