CVE-2026-65604

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.
Configurations

No configuration.

History

24 Jul 2026, 15:19

Type Values Removed Values Added
References () https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734 - () https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734 -

23 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-23 22:16

Updated : 2026-07-30 19:53


NVD link : CVE-2026-65604

Mitre link : CVE-2026-65604

CVE.ORG link : CVE-2026-65604


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation