HTTP Router Vulnerability in Skipper by Zalando
CVE-2026-65838

8.2HIGH

Key Information:

Vendor

Zalando

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-65838?

The Skipper HTTP router experienced a vulnerability that allows an oversized declared Content-Length request to bypass the deny-on-presence Rego policy in prior versions. This occurs because the opaAuthorizeRequestWithBody filter can forward the complete request body upstream without adequately evaluating the authorization conditions, particularly when the body size exceeds a predefined limit. As a result, improperly handled payloads may be allowed to reach protected services, making it crucial for users to update to version 0.27.35 or later to mitigate this risk.

Affected Version(s)

skipper < 0.27.35

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.