PT-2026-93918 · Kipper+1 · Kipper+1

CVE-2026-86043

·

Published

2026-09-16

·

Updated

2026-09-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Skipper versions prior to 0.27.37
Description Skipper is an HTTP router and reverse proxy for service composition. The opaAuthorizeRequestWithBody filter can authorize oversized requests by incorrectly signaling the truncation state to the Open Policy Agent (OPA). When a request body exceeds the configured maximum size, Skipper truncates the body before sending it to OPA. However, the input.truncated body signal is derived from the Content-Length header rather than the actual read result.
For HTTP/1.1 requests using Transfer-Encoding: chunked or HTTP/2 requests without a Content-Length header, the input.truncated body variable remains false even if the body was truncated. A security policy that permits requests where input.truncated body is false will evaluate only the truncated prefix, authorize the request, and subsequently forward the full oversized body to the protected upstream server. This allows a bypass of request-body authorization for oversized or un-inspectable payloads.
Technical details include:
  • API Endpoints: The issue affects requests processed by the opaAuthorizeRequestWithBody filter.
  • Vulnerable Parameters or Variables: The input.truncated body variable is incorrectly calculated.
  • Function Names: The vulnerability involves ExtractHttpBodyOptionally() in filters/openpolicyagent/openpolicyagent.go and the getParsedBody() and checkIfHTTPBodyTruncated() functions within the OPA envoy plugin.
Recommendations Update Skipper to version 0.27.37. As a temporary mitigation, avoid relying solely on the input.truncated body variable for authorization decisions in OPA policies when handling chunked or HTTP/2 requests.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86043
GHSA-5GPM-RGJ3-9Q76
GO-2026-6495

Affected Products

Open Policy Agent
Kipper