Policy Bypass Vulnerability in Skipper by Zalando
CVE-2026-65604
8.8HIGH
What is CVE-2026-65604?
Skipper, developed by Zalando, suffers from a policy bypass vulnerability due to an incomplete fix for a previous issue. When oversized request bodies exceed the designated maximum allowed size, Skipper allows these requests to pass through to the upstream service without properly enforcing the Open Policy Agent (OPA) deny-on-presence Rego policies. This creates a significant security risk as it permits forbidden actions based on content that should have been denied, resulting in a potential breach of application integrity. As of now, there is no patched version available; version v0.27.26 only provides additional documentation without resolving the issue.
