Zalando's vulnerability footprint is centered on its Skipper reverse-proxy and load-balancing platform, a component that sits in the request path of its e-commerce and platform infrastructure. The observed weakness classes, including server-side request forgery, code injection, and credential handling issues, reflect the parsing and privilege-elevation risks inherent to a gateway component that mediates access to backend services. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zalando over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38580CRITICAL Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). | Oct 25, 2022 | 9.8 | 51 | NO | YES |
CVE-2026-23742HIGH Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted u | Jan 16, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-24470HIGH Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ing | Jan 26, 2026 | 8.1 | 27 | NO | NO |
CVE-2022-34296HIGH In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request. | Jun 23, 2022 | 7.5 | 24 | NO | NO |
CVE-2026-65604HIGH Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds t | Jul 23, 2026 | 8.2 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zalando.
Media articles that mention a CVE ID that affects a product developed by Zalando — matched by CVE ID, not by vendor name.