Skipper 是用于服务组合(service composition)的 HTTP 路由器和反向代理。在 0.27.13 版本之前,routesrv 组件通过 、 、 和 端点提供整个集群范围内的控制平面数据,但未启用应用层身份验证。 具体而言, 中注册的处理程序、 中的 、 中的 以及 中的 仅限制了 HTTP 方法,但未对调用方进行身份验证。 因此,一个被攻陷或受攻击者控制的、能够访问 Kubernetes 集群网络中 routesrv 的 Pod,可以绕过其命名空间范围内的 RBAC(基于角色的访问控制),
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65838 | 8.2 HIGH | Skipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body |
| CVE-2026-54247 | 4.3 MEDIUM | Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS |
No comments yet