Looking for the vulnerability index of Invicti's legacy products?
Skipper : Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-54247) - Vulnerability Database

Skipper : Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-54247)

Description

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size limit. An attacker with in-cluster network access and a valid Kubernetes client certificate can send a very large body that causes unbounded memory allocation and an out-of-memory termination of the Skipper process. The disrup

References