PT-2026-91455 · Kipper · Kipper

CVE-2026-65838

·

Published

2026-07-17

·

Updated

2026-09-15

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Skipper versions prior to 0.27.35
Description An issue exists in the opaAuthorizeRequestWithBody filter within filters/openpolicyagent/openpolicyagent.go where requests with a declared Content-Length exceeding the -open-policy-agent-max-request-body-size (defaulting to 1 MB) can bypass deny-on-presence Rego policies. This occurs because the ExtractHttpBodyOptionally() function provides an empty parsed body to the Open Policy Agent (OPA) while still forwarding the full request body to the upstream service. Consequently, policy logic that does not explicitly reject the input.attributes.request.http.truncated body variable may fail open, allowing forbidden payloads to reach the protected service.
Recommendations Update Skipper to version 0.27.35. As a mitigation measure, policy owners should modify Rego policies to block requests with oversized bodies by checking the input.attributes.request.http.truncated body variable.

Exploit

Fix

HTTP Request/Response Smuggling

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65838
GHSA-8QQM-FP2Q-V734
GO-2026-6019

Affected Products

Kipper