Impact
Skipper, a service composition router and reverse proxy, uses an opaAuthorizeRequestWithBody filter to enforce body size limits through Open Policy Agent. A truncation of the request body occurs during processing, but the signal indicating truncation (input.truncated_body) is derived from the reported Content‑Length header rather than the actual body length that Skipper reads. For HTTP/1.1 requests that employ Transfer‑Encoding: chunked or HTTP/2 requests that omit a Content‑Length header, the upstream policy can see only the truncated prefix. If its rule permits input.truncated_body equal to false, the policy approves the request and Skipper then forwards the entire oversized body to the protected upstream service. This allows an attacker to bypass body‑size restrictions, potentially overwhelming downstream services or delivering a payload that exceeds intended limits.
Affected Systems
The affected product is Zalando Skipper. Versions prior to 0.27.37, including release 0.27.35, contain the vulnerability. The issue is fixed in Skipper 0.27.37 and later.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity. The EPSS score of less than 1% shows a low current likelihood of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is network‑based; an attacker who can send crafted HTTP/1.1 chunked or HTTP/2 requests to the Skipper instance can exploit the flaw. Because the vulnerability hinges on policy logic and header handling, it does not require privileged access, making it broadly exploitable under the right circumstances.
OpenCVE Enrichment
Github GHSA