zalando
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 6
en
Verify to analyze this security profile
As of 09/17/2026, zalando recorded 6 security vulnerabilities in the last 90 days across 1 products, including 4 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, skipper had the most security vulnerabilities in the zalando ecosystem, with 6 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-54247Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS | Exploitation statusNot confirmed | FixYes | Affected productskipper | Published09/14/2026 | SeverityMedium |
CVE-2026-54246Skipper routesrv-no-auth: All routesrv API Endpoints Lack Authentication | Exploitation statusNot known exploited | FixYes | Affected productskipper | Published09/14/2026 | SeverityMedium |
CVE-2026-65838Skipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego policies fail OPEN while the full payload reaches upstream | Exploitation statusNot known exploited | FixYes | Affected productskipper | Published09/14/2026 | SeverityHigh |
CVE-2026-65604Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass | Exploitation statusPublic exploit | FixNot confirmed | Affected productskipper | Published07/23/2026 | SeverityHigh |
CVE-2026-50197Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding: chunked / HTTP/2 requests | Exploitation statusPublic exploit | FixYes | Affected productskipper | Published07/17/2026 | SeverityHigh |
CVE-2026-24470Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName | Exploitation statusNot known exploited | FixNot confirmed | Affected productskipper | Published01/26/2026 | SeverityHigh |
CVE-2026-23742Skipper arbitrary code execution through lua filters | Exploitation statusNot known exploited | FixYes | Affected productskipper | Published01/16/2026 | SeverityHigh |
CVE-2022-38580 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published10/24/2022 | SeverityCritical |
CVE-2022-34296 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published06/22/2022 | SeverityUnknown |