Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-23 22:16
Updated : 2026-07-30 19:53
NVD link : CVE-2026-65604
Mitre link : CVE-2026-65604
CVE.ORG link : CVE-2026-65604
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
