Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network access to reach internal services. Version 0.24.0 disables Kubernetes ExternalName by default. As a workaround, developers can allow list targets of an ExternalName and allow list via regular expressions.
References
Configurations
History
18 Feb 2026, 17:39
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Zalando skipper
Zalando |
|
| CPE | cpe:2.3:a:zalando:skipper:*:*:*:*:*:*:*:* | |
| References | () https://github.com/zalando/skipper/commit/a4c87ce029a58eb8e1c2c1f93049194a39cf6219 - Patch | |
| References | () https://github.com/zalando/skipper/security/advisories/GHSA-mxxc-p822-2hx9 - Vendor Advisory, Mitigation | |
| References | () https://kubernetes.io/docs/concepts/services-networking/service/#externalname - Product |
26 Jan 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-26 23:16
Updated : 2026-02-18 17:39
NVD link : CVE-2026-24470
Mitre link : CVE-2026-24470
CVE.ORG link : CVE-2026-24470
JSON object : View
Products Affected
zalando
- skipper
