Skipper 是一个用于服务组合的 HTTP 路由器和反向代理。在 0.26.22 版本之前, 中的 Handler 在将请求的 body 传递到 Kubernetes 准入端点 时,直接使用 读取请求体,且未设置大小限制。拥有集群内网络访问权限并持有有效 Kubernetes 客户端证书的攻击者可以发送一个非常大的请求体,从而导致无界的内存分配,最终引起 Skipper 进程因内存溢出(OOM)而终止。该故障的影响范围仅限于 Ingress 和 RouteGroup 的准入控制,而非 Pod 创建或其他无关的准
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65838 | 8.2 HIGH | Skipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body |
| CVE-2026-54246 | 5.7 MEDIUM | Skipper routesrv-no-auth: All routesrv API Endpoints Lack Authentication |
No comments yet