Impact
An HTTP router upgrade route can process an oversized declared Content-Length request without fully transferring the body to the Open Policy Agent. The Skipper filter opaAuthorizeRequestWithBody calls ExtractHttpBodyOptionally and extracts an empty parsed_body, but still forwards the full payload upstream. As a result, any deny‑on‑presence Rego policy that relies on the presence of a request body fails to trigger; the upstream service therefore receives a disallowed payload and is exposed to potential unauthorized actions. The flaw is specific to Zalando Skipper components, especially the opaAuthorizeRequestWithBody filter, in versions prior to 0.27.35. Deployments that enable request‑body authorization and permit bodies larger than the default Open Policy Agent maximum request body size of 1 MB are vulnerable.
Affected Systems
Zalando Skipper, version 0.27.34 and earlier, including the opaAuthorizeRequestWithBody filter, are affected.
Risk and Exploitability
The CVSS score of 8.2 indicates a high‑severity risk. The EPSS score is below 1 %, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack would require an adversary to send an HTTP request with a large body; the vulnerability is therefore deemed remote, but this assessment is inferred from the nature of the component and the described attack vector.
OpenCVE Enrichment
Github GHSA