VulnerabilitiesSkipper OPA body checks fail open on chunked requests
An advisory published on 17 September 2026 says Zalando's Skipper proxy still lets oversized request bodies slip past Open Policy Agent checks.
17 Sept 2026
Skipper's OPA authorization filter fails to properly detect truncated request bodies when using chunked transfer encoding or HTTP/2, allowing oversized payloads to bypass policy inspection. This is an incomplete fix to a prior vulnerability.
Disclosed 17 September 2026 · Record updated 17 September 2026
Attackers can bypass OPA-based authorization policies by sending oversized request bodies via chunked encoding or HTTP/2, allowing malicious payloads to reach upstream services without inspection.
VulnerabilitiesAn advisory published on 17 September 2026 says Zalando's Skipper proxy still lets oversized request bodies slip past Open Policy Agent checks.
17 Sept 2026