CVE-2026-24470
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network access to reach internal services. Version 0.24.0 disables Kubernetes ExternalName by default. As a workaround, developers can allow list targets of an ExternalName and allow list via regular expressions.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-441, CWE-918
- Published
- 2026-01-26
- Last modified
- 2026-03-12
Affected products
- zalando skipper
Weakness type
Related vulnerabilities
- CVE-2026-87502 — Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who...
- CVE-2026-87582 — Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87442 — Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who...
- CVE-2026-87453 — Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-69531 — Microsoft Windows Speech Tampering Vulnerability
- CVE-2026-86600 — Workload identity attestation generated before login host validation in Snowflake drivers
- CVE-2026-86115 — Sim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token for a User-Supplied /api/ Path
- CVE-2026-84329 — Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed...