HTTP Router Vulnerability in Skipper by Zalando
CVE-2026-65838
8.2HIGH
What is CVE-2026-65838?
The Skipper HTTP router experienced a vulnerability that allows an oversized declared Content-Length request to bypass the deny-on-presence Rego policy in prior versions. This occurs because the opaAuthorizeRequestWithBody filter can forward the complete request body upstream without adequately evaluating the authorization conditions, particularly when the body size exceeds a predefined limit. As a result, improperly handled payloads may be allowed to reach protected services, making it crucial for users to update to version 0.27.35 or later to mitigate this risk.
Affected Version(s)
skipper < 0.27.35
