{"id":"CVE-2026-24470","aliases":["GHSA-mxxc-p822-2hx9","GO-2026-4378"],"url":"https://o3.security/vulnerability/CVE-2026-24470","summary":"Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName","details":"Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network access to reach internal services. Version 0.24.0 disables Kubernetes ExternalName by default. As a workaround, developers can allow list targets of an ExternalName and allow list via regular expressions.","published":"2026-01-26T22:23:43.325Z","modified":"2026-08-12T03:51:26.480036789Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.00267,"percentile":0.18359,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/zalando/skipper","fixedVersion":"0.24.0"}],"fix":{"url":"https://github.com/zalando/skipper/commit/a4c87ce029a58eb8e1c2c1f93049194a39cf6219","label":"zalando/skipper@a4c87ce"},"references":[{"type":"WEB","url":"https://kubernetes.io/docs/concepts/services-networking/service/#externalname"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24470.json"},{"type":"ADVISORY","url":"https://github.com/zalando/skipper/security/advisories/GHSA-mxxc-p822-2hx9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24470"},{"type":"FIX","url":"https://github.com/zalando/skipper/commit/a4c87ce029a58eb8e1c2c1f93049194a39cf6219"},{"type":"PACKAGE","url":"https://github.com/zalando/skipper"},{"type":"WEB","url":"https://github.com/zalando/skipper/releases/tag/v0.24.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.480036789Z"}}