CVE-2022-38580
Critical · CVSS 9.8github.com/zalando/skipper — Server-Side Request Forgery (SSRF)
- CVSS
- 9.8
- nvd
- EPSS
- 11.0%
- 95th pct
- KEV
- No
- Class
- oss containerizable
- CWE-918
Description
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
Search profile — drives PoC discovery
Symbols X-Skipper-ProxyskipperSSRFproxyCVE-2022-38580
Keywords CVE-2022-38580Zalando Skipper SSRFX-Skipper-Proxy SSRFskipper proxy server-side request forgeryzalando skipper 0.13.236zalando skipper 0.13.237
Versions: v0.13.236 – v0.13.237
Ranked PoCs (3) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0trickest
- ★ 0Moaz-Awad/PENTESTING-REPORT-FOR-HTB-LANTERN-MACHINE needs reviewtrickest
- ★ 0cokeBeer/go-cves needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Go | github.com/zalando/skipper | 0 → 0.13.237 |
References
- http://packetstormsecurity.com/files/171546/X-Skipper-Proxy-0.13.237-Server-Side-Request-Forgery.html
- https://gist.github.com/Fadavvi/9fffcfa4aaa9e25b77cfe7b3044b2857#file-cve-2022-38580
- https://pastebin.com/dXxpgPAK
- http://packetstormsecurity.com/files/171546/X-Skipper-Proxy-0.13.237-Server-Side-Request-Forgery.html
- http://skipper.com
- http://zalando.com
- https://gist.github.com/Fadavvi/9fffcfa4aaa9e25b77cfe7b3044b2857#file-cve-2022-38580
- https://pastebin.com/dXxpgPAK
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z