Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass
Vulnerability Description
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
zalando Skipper 输入验证错误漏洞
Vulnerability Description
zalando Skipper是德国zalando公司开源的一个HTTP路由器和反向代理。 zalando Skipper存在输入验证错误漏洞,该漏洞源于对已知错误的不完整修复,导致超大的请求体绕过Open Policy Agent (OPA) deny-on-presence Rego策略。当请求体超过配置的maxBodyBytes限制时,Skipper将完整有效载荷转发到上游服务而OPA对空的parsed_body进行评估,因此基于请求体内容拒绝请求的策略不被执行,禁止的操作继续进行。
CVSS Information
N/A
Vulnerability Type
N/A