CVE-2026-65604
HIGHSkipper Incomplete Fix for CVE-2026-50197 Policy Bypass
Title source: cnaDescription
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-8qqm-fp2q-v734)
https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734
Third Party Advisory third-party-advisory
VulnCheck Advisory: Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass
https://www.vulncheck.com/advisories/skipper-incomplete-fix-for-cve-2026-50197-policy-bypass
Scores
CVSS v3
8.2
EPSS
0.0029
EPSS Percentile
21.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (1)
zalando/skipper
Published
Jul 23, 2026
Tracked Since
Jul 24, 2026