Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only. | |
| Title | Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass | |
| First Time appeared |
Zalando
Zalando skipper |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:a:zalando:skipper:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zalando
Zalando skipper |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-23T21:16:47.608Z
Reserved: 2026-07-22T10:48:36.000Z
Link: CVE-2026-65604
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T02:15:04Z
Weaknesses