CVE-2026-65838
Last modified
CVE-2026-65838 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with an empty parsed_body while forwarding the complete request body upstream. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with an empty parsed_body while forwarding the complete request body upstream. This incomplete remediation of CVE-2026-50197 affects deployments that authorize request-body content and exceed -open-policy-agent-max-request-body-size, which defaults to 1 MB. Policy logic that does not reject input.attributes.request.http.truncated_body can therefore fail open and permit a forbidden payload to reach the protected service, while small bodies and the previously fixed chunked-body case are evaluated normally. This issue is fixed in version 0.27.35.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| zalando | skipper | < 0.27.35 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-65838?
How severe is CVE-2026-65838?
How do I fix CVE-2026-65838?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-65829MPXJ is an open source library to read and write project pla…5.3
- CVE-2026-6583A vulnerability has been found in TransformerOptimus SuperAG…5.4
- CVE-2026-65831ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-ro…7.7
- CVE-2026-65832Deskflow is a keyboard and mouse sharing app. Prior to conti…8.2
- CVE-2026-65834Capsule is a multi-tenancy and policy-based framework for Ku…6.8
- CVE-2026-65835Capsule is a multi-tenancy and policy-based framework for Ku…6.6
- CVE-2026-6584A vulnerability was found in TransformerOptimus SuperAGI up …5.4
- CVE-2026-65841Jodit Editor is a WYSIWYG editor with a built-in file browse…5.3
- CVE-2026-65842Plate is a rich-text editor with AI and shadcn/ui. Prior to …8.2
- CVE-2026-6585A vulnerability was determined in TransformerOptimus SuperAG…5.4
- CVE-2026-6586A vulnerability was identified in TransformerOptimus SuperAG…6.3
- CVE-2026-6587A security flaw has been discovered in vibrantlabsai RAGAS u…6.3
Are you affected by CVE-2026-65838?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
