Looking for the vulnerability index of Invicti's legacy products?
Skipper Unintended Proxy or Intermediary (Confused Deputy) Vulnerability - CVE-2026-24470 - Vulnerability Database

Skipper Unintended Proxy or Intermediary (Confused Deputy) Vulnerability - CVE-2026-24470

High
Reference: CVE-2026-24470
Title: Skipper Unintended Proxy or Intermediary (Confused Deputy) Vulnerability
Overview:

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0 when running Skipper as an Ingress controller users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper39s network access to reach internal services. Version 0.24.0 disables Kubernetes ExternalName by default. As a workaround developers can allow list targets of an ExternalName and allow list via regular expressions.