CVE-2026-65604

HIGH

Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass

Title source: cna
STIX 2.1

Description

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-8qqm-fp2q-v734)
https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734
Third Party Advisory third-party-advisory
VulnCheck Advisory: Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass
https://www.vulncheck.com/advisories/skipper-incomplete-fix-for-cve-2026-50197-policy-bypass

Scores

CVSS v3 8.2
EPSS 0.0029
EPSS Percentile 21.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
zalando/skipper
Published Jul 23, 2026
Tracked Since Jul 24, 2026