Description
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size limit. An attacker with in-cluster network access and a valid Kubernetes client certificate can send a very large body that causes unbounded memory allocation and an out-of-memory termination of the Skipper process. The disruption is limited to Ingress and RouteGroup admission rather than pod creation or unrelated admission controllers, and Kubernetes normally restarts the process. This issue is fixed in version 0.26.22.
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Exhaustion DoS via unbounded request body read
Action: Upgrade Now
AI Analysis

Impact

The vulnerability lies in Skipper’s admission handler located in dataclients/kubernetes/admission/admission.go, which forwards HTTP request bodies to the Kubernetes admission endpoint at :9443/admission by passing r.Body directly to io.ReadAll without a size limit. An attacker with in-cluster network access and a valid Kubernetes client certificate can send an arbitrarily large body, causing Skipper to allocate memory until host RAM is exhausted and terminate with an out‑of‑memory error. The resulting denial of service is limited to Ingress and RouteGroup admission; Kubernetes normally restarts the Skipper process, mitigating persistentalando Skipper installations running any version earlier than 0.26.22. The vulnerability resides in the dataclients/kubernetes/admission/admission.go component, which forwards request bodies :9443/admission without imposing a size limit. The DoS impacts only Ingress and RouteGroup admission, not pod creation or other admission controllers. Custom or forked builds that include the same unbounded read path are also affected; versions 0.26.22 and later are not vulnerable.

Affected Systems

Zalando Skipper versions prior to 0.26.22 are affected, particularly the admission webhook path in dataclients/kubernetes/admission. Only the Skipper component handling Ingress and RouteGroup admission is impacted; all other components and later releases are not vulnerable. The default deployment operates with in‑cluster network access and a Kubernetes client certificate, so any in‑cluster workload with admission privileges could be used to trigger the issue.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity. The EPSS score is below 1%, suggesting a very low probability of exploitation in the wild. This vulnerability is not listed in CISA KEV. Exploitation requires in‑cluster network connectivity and a legitimate Kubernetes client certificate, which are typically limited to internal service accounts or trusted workloads. Once the conditions are met, the attacker can trigger an out‑of‑memory crash, but Kubernetes’ automatic restarts mitigate persistent disruption. The overall risk is modest, yet the lack of a hard limit on request size can be leveraged for a DoS attack if no mitigations are applied.

Generated by OpenCVE AI on September 20, 2026 at 22:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Skipper to version 0.26.22 or later to apply the fix that enforces a body size limit.
  • If immediate upgrade is not possible, restrict large in‑cluster traffic by applying Kubernetes NetworkPolicies that limit request sizes or deny traffic from untrusted namespaces to the Skipper admission webhook on port 9443.
  • Monitor Skipper’s memory usage and the Kubernetes admission controller logs; if out‑of‑memory events occur, verify that the process restarts and run resilience checks to ensure traffic is restored promptly

Generated by OpenCVE AI on September 20, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cwxq-rc9x-2jvv Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS
History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Zalando
Zalando skipper
Vendors & Products Zalando
Zalando skipper

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size limit. An attacker with in-cluster network access and a valid Kubernetes client certificate can send a very large body that causes unbounded memory allocation and an out-of-memory termination of the Skipper process. The disruption is limited to Ingress and RouteGroup admission rather than pod creation or unrelated admission controllers, and Kubernetes normally restarts the process. This issue is fixed in version 0.26.22.
Title Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T16:19:12.336Z

Reserved: 2026-06-12T16:25:43.085Z

Link: CVE-2026-54247

cve-icon Vulnrichment

Updated: 2026-09-16T16:19:07.735Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:45.843

Modified: 2026-09-16T17:17:20.600

Link: CVE-2026-54247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling