CVE-2026-65604: Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass

Published Jul 23, 2026
·
Updated

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsedbody, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.

Affected Software

1 affected component
skipper=0.27.26

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Until the incomplete fix for CVE-2026-50197 is resolved, mitigate the policy bypass by ensuring Skipper does not forward oversized request bodies to the upstream service when the request body exceeds the configured maxBodyBytes limit (so OPA policies that rely on body content are not evaluated against an empty parsed_body).

Event History

Jul 23, 2026
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-65604?

The severity of CVE-2026-65604 is high, rated at 8.2.

2

How do I fix CVE-2026-65604?

To fix CVE-2026-65604, ensure you apply the latest patches and updates provided for Skipper that address the policy bypass issues.

3

What impact does CVE-2026-65604 have on my application?

CVE-2026-65604 allows oversized request bodies to bypass Open Policy Agent evaluations, potentially exposing sensitive data.

4

Which software is affected by CVE-2026-65604?

CVE-2026-65604 affects the Skipper software.

5

What types of attacks can exploit CVE-2026-65604?

CVE-2026-65604 can be exploited through denial of service or unauthorized access due to policy bypasses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203