PT-2026-91455 · Kipper · Kipper
CVE-2026-65838
·
Published
2026-07-17
·
Updated
2026-09-15
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Skipper versions prior to 0.27.35
Description
An issue exists in the
opaAuthorizeRequestWithBody filter within filters/openpolicyagent/openpolicyagent.go where requests with a declared Content-Length exceeding the -open-policy-agent-max-request-body-size (defaulting to 1 MB) can bypass deny-on-presence Rego policies. This occurs because the ExtractHttpBodyOptionally() function provides an empty parsed body to the Open Policy Agent (OPA) while still forwarding the full request body to the upstream service. Consequently, policy logic that does not explicitly reject the input.attributes.request.http.truncated body variable may fail open, allowing forbidden payloads to reach the protected service.Recommendations
Update Skipper to version 0.27.35.
As a mitigation measure, policy owners should modify Rego policies to block requests with oversized bodies by checking the
input.attributes.request.http.truncated body variable.Exploit
Fix
HTTP Request/Response Smuggling
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kipper