Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.
References
Configurations
No configuration.
History
24 Jul 2026, 15:19
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734 - |
23 Jul 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-23 22:16
Updated : 2026-07-30 19:53
NVD link : CVE-2026-65604
Mitre link : CVE-2026-65604
CVE.ORG link : CVE-2026-65604
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
