Looking for the vulnerability index of Invicti's legacy products?
Skipper : Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2026-65838) - Vulnerability Database

Skipper : Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2026-65838)

Description

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with an empty parsed_body while forwarding the complete request body upstream. This incomplete remediation of CVE-2026-50197 affects deployments that authorize request-body content and ex

References