CVE-2026-24470

S

kipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network access to reach internal services. Version 0.24.0 disables Kubernetes ExternalName by default. As a workaround, developers can allow list targets of an ExternalName and allow list via regular expressions.

Configurations

Configuration 1 (hide)

cpe:2.3:a:zalando:skipper:*:*:*:*:*:*:*:*

History

18 Feb 2026, 17:39

Type Values Removed Values Added
First Time Zalando skipper
Zalando
CPE cpe:2.3:a:zalando:skipper:*:*:*:*:*:*:*:*
References () https://github.com/zalando/skipper/commit/a4c87ce029a58eb8e1c2c1f93049194a39cf6219 - () https://github.com/zalando/skipper/commit/a4c87ce029a58eb8e1c2c1f93049194a39cf6219 - Patch
References () https://github.com/zalando/skipper/security/advisories/GHSA-mxxc-p822-2hx9 - () https://github.com/zalando/skipper/security/advisories/GHSA-mxxc-p822-2hx9 - Vendor Advisory, Mitigation
References () https://kubernetes.io/docs/concepts/services-networking/service/#externalname - () https://kubernetes.io/docs/concepts/services-networking/service/#externalname - Product

26 Jan 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 23:16

Updated : 2026-02-18 17:39


NVD link : CVE-2026-24470

Mitre link : CVE-2026-24470

CVE.ORG link : CVE-2026-24470


JSON object : View

Products Affected
CWE
CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')

CWE-918

Server-Side Request Forgery (SSRF)