CVE-2026-54247

medium

Description

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size limit. An attacker with in-cluster network access and a valid Kubernetes client certificate can send a very large body that causes unbounded memory allocation and an out-of-memory termination of the Skipper process. The disruption is limited to Ingress and RouteGroup admission rather than pod creation or unrelated admission controllers, and Kubernetes normally restarts the process. This issue is fixed in version 0.26.22.

References

https://github.com/zalando/skipper/security/advisories/GHSA-cwxq-rc9x-2jvv

https://github.com/zalando/skipper/releases/tag/v0.26.22

https://github.com/zalando/skipper/pull/4053

https://github.com/zalando/skipper/commit/c3d156c6caaefecc9a46774c0f9c3c70b97160b4

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-78062

Details

Source: Mitre, NVD

Published: 2026-09-14

Updated: 2026-09-16

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

EPSS

EPSS: 0.00227