Policy Bypass Vulnerability in Skipper by Zalando
CVE-2026-65604

8.8HIGH

Key Information:

Vendor

Zalando

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-65604?

Skipper, developed by Zalando, suffers from a policy bypass vulnerability due to an incomplete fix for a previous issue. When oversized request bodies exceed the designated maximum allowed size, Skipper allows these requests to pass through to the upstream service without properly enforcing the Open Policy Agent (OPA) deny-on-presence Rego policies. This creates a significant security risk as it permits forbidden actions based on content that should have been denied, resulting in a potential breach of application integrity. As of now, there is no patched version available; version v0.27.26 only provides additional documentation without resolving the issue.

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sec-reex
.