{"id":"GHSA-8qqm-fp2q-v734","summary":"Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies","details":"### Summary\n\nA wrong policy can be an open door. \nYou have to check `input.attributes.request.http.truncated_body` in your policy.\n\n### Description\n\nIncomplete fix for CVE-2026-50197: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego policies fail OPEN while the full payload reaches upstream.\n\nThe CVE-2026-50197 fix (commit `3152f3b0`, PR #4041, v0.26.10) substituted `expectedSize = maxBodyBytes`\nonly when `req.ContentLength \u003c 0` (chunked / HTTP/2 without content-length). But when a request declares a\n`Content-Length` larger than `maxBodyBytes`, `expectedSize \u003e maxBodyBytes`, the body-extraction `if` is\nskipped entirely, and `ExtractHttpBodyOptionally` returns `rawBodyBytes = nil` — so OPA evaluates an empty\n`parsed_body`, while the full forbidden payload still flows to the upstream. A deny-on-presence policy\n(`default allow = true; allow = false if input.parsed_body.\u003cforbidden\u003e`) — the exact Rego shape the\nadvisory describes — fails OPEN. The fix's own comment reasons only about `ContentLength == -1`; the\noversized branch was never considered, and the added PoC test only covers small bodies.\n\n### Affected code\n\n- `filters/openpolicyagent/openpolicyagent.go` `ExtractHttpBodyOptionally`: the\n  `expectedSize \u003c= maxBodyBytes` gate lets an oversized declared body fall through to\n  `return req.Body, nil, func() {}, nil` (OPA sees an empty document).\n- Corroborated by Skipper's own unit test \"Read body exhausting max bytes\" (`{ \"welcome\": \"world\" }`,\n  `maxBodySize: 5` → `bodyInPolicy: \"\"`).\n\n### Steps to reproduce\n\nSee attached `docker-compose.yml` (official `golang` image) + `setup.sh` + `exploit.sh`, which run a real\nSkipper proxy (`proxytest`) with a real OPA control plane (`opasdktest`),\n`WithMaxRequestBodyBytes(32)`, policy `allow = false if input.parsed_body.action == \"delete\"`, route\n`* -\u003e opaAuthorizeRequestWithBody(\"test\") -\u003e upstream`:\n- `{\"action\":\"delete\"}` (19B ≤ 32) → **403** (denied).\n- `{\"action\":\"delete\",\"pad\":\"X..64\"}` (\u003e 32) → **200**, upstream received the full body (BYPASS).\n- small chunked `{\"action\":\"delete\"}` → **403** (positive control: the original CVE is fixed).\n\n(Library-tier: validated via Skipper's real proxy test harness, not a deploy of the official image; benign\noracle = status diff + upstream-received body; no RCE.)\n\n### Impact\n\nDeployments authorizing on request-body content via `opaAuthorizeRequestWithBody` + deny-on-presence Rego\ncan be bypassed by inflating the request body past `-open-policy-agent-max-request-body-size` (default\n1 MB); the full payload still reaches the upstream.\n\n### Mitigation\n\nDocument how policy owners should block requests with oversized body.\n\nExample deny by default and use \"allow if\" no oversized body:\n```rego\ndefault allow := false\n\nallow if {\n    input.attributes.request.http.truncated_body == false\n    # ... body-based conditions\n}\n```\n\nExample allow by default and use \"deny if\" an oversized body:\n```rego\ndefault deny := false\n\ndeny if {\n    input.attributes.request.http.truncated_body == true\n    # ... body-based conditions\n}\n```\n\nDocumentation is published by https://github.com/zalando/skipper/releases/tag/v0.27.26\n\n### Credit\n\nReported as part of an incomplete-patch measurement study (responsible disclosure).","aliases":["CVE-2026-65838","GO-2026-6019"],"modified":"2026-09-25T17:15:05.948244239Z","published":"2026-07-17T21:49:48Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-17T21:49:48Z","nvd_published_at":"2026-09-14T20:16:49Z","cwe_ids":["CWE-444"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65838"},{"type":"WEB","url":"https://github.com/zalando/skipper/commit/2cfceabaa6ff0af65b312dcb9bcbe84691b9d507"},{"type":"PACKAGE","url":"https://github.com/zalando/skipper"},{"type":"WEB","url":"https://github.com/zalando/skipper/releases/tag/v0.27.26"},{"type":"WEB","url":"https://github.com/zalando/skipper/releases/tag/v0.27.35"}],"affected":[{"package":{"name":"github.com/zalando/skipper","ecosystem":"Go","purl":"pkg:golang/github.com/zalando/skipper"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.27.26"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8qqm-fp2q-v734/GHSA-8qqm-fp2q-v734.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}