Description
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with an empty parsed_body while forwarding the complete request body upstream. This incomplete remediation of CVE-2026-50197 affects deployments that authorize request-body content and exceed -open-policy-agent-max-request-body-size, which defaults to 1 MB. Policy logic that does not reject input.attributes.request.http.truncated_body can therefore fail open and permit a forbidden payload to reach the protected service, while small bodies and the previously fixed chunked-body case are evaluated normally. This issue is fixed in version 0.27.35.
Published: 2026-09-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Policy Bypass
Action: Immediate Patch
AI Analysis

Impact

An HTTP router upgrade route can process an oversized declared Content-Length request without fully transferring the body to the Open Policy Agent. The Skipper filter opaAuthorizeRequestWithBody calls ExtractHttpBodyOptionally and extracts an empty parsed_body, but still forwards the full payload upstream. As a result, any deny‑on‑presence Rego policy that relies on the presence of a request body fails to trigger; the upstream service therefore receives a disallowed payload and is exposed to potential unauthorized actions. The flaw is specific to Zalando Skipper components, especially the opaAuthorizeRequestWithBody filter, in versions prior to 0.27.35. Deployments that enable request‑body authorization and permit bodies larger than the default Open Policy Agent maximum request body size of 1 MB are vulnerable.

Affected Systems

Zalando Skipper, version 0.27.34 and earlier, including the opaAuthorizeRequestWithBody filter, are affected.

Risk and Exploitability

The CVSS score of 8.2 indicates a high‑severity risk. The EPSS score is below 1 %, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack would require an adversary to send an HTTP request with a large body; the vulnerability is therefore deemed remote, but this assessment is inferred from the nature of the component and the described attack vector.

Generated by OpenCVE AI on September 20, 2026 at 22:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Skipper to version 0.27.35 or later.
  • If an update cannot be performed immediately, reduce the Open Policy Agent maximum request body size setting, or modify Rego policies to explicitly reject bodies flagged as truncated.
  • Monitor Skipper logs for large request attempts and verify that policy logs show rejections for oversized payloads.

Generated by OpenCVE AI on September 20, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8qqm-fp2q-v734 Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Zalando
Zalando skipper
Vendors & Products Zalando
Zalando skipper

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with an empty parsed_body while forwarding the complete request body upstream. This incomplete remediation of CVE-2026-50197 affects deployments that authorize request-body content and exceed -open-policy-agent-max-request-body-size, which defaults to 1 MB. Policy logic that does not reject input.attributes.request.http.truncated_body can therefore fail open and permit a forbidden payload to reach the protected service, while small bodies and the previously fixed chunked-body case are evaluated normally. This issue is fixed in version 0.27.35.
Title Skipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego policies fail OPEN while the full payload reaches upstream
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:55:41.273Z

Reserved: 2026-07-22T23:16:47.753Z

Link: CVE-2026-65838

cve-icon Vulnrichment

Updated: 2026-09-15T13:26:57.437Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:49.103

Modified: 2026-09-16T13:42:48.383

Link: CVE-2026-65838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions