Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

Skipper OPA body-authz bypass with chunked/HTTP-2 requests

Skipper's OPA authorization filter fails to properly detect truncated request bodies when using chunked transfer encoding or HTTP/2, allowing oversized payloads to bypass policy inspection. This is an incomplete fix to a prior vulnerability.

Disclosed 17 September 2026 · Record updated 17 September 2026

Impact

Attackers can bypass OPA-based authorization policies by sending oversized request bodies via chunked encoding or HTTP/2, allowing malicious payloads to reach upstream services without inspection.

Our coverage

Sources

  1. github.comhttps://github.com/advisories/GHSA-5gpm-rgj3-9q76