GHSA-8qqm-fp2q-v734
### Summary A wrong policy can be an open door. You have to check `input.attributes.request.http.truncated_body` in your policy. ### Description Incomplete fix for CVE-2026-50197: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego policies fail OPEN while the full payload reaches upstream. The CVE-2026-50197 fix (commit `3152f3b0`, PR #4041, v0.26.10) substituted `expectedSize = maxBodyBytes` only when `req.ContentLength < 0` (chunked / HTTP/2 without content-length). But when a request declares a `Content-Length` larger than `maxBodyBytes`, `expectedSize > maxBodyBytes`, the body-extraction `if` is skipped entirely, and `ExtractHttpBodyOptionally` returns `rawBodyBytes = nil` — so OPA evaluates an empty `parsed_body`, while the full forbidden payload still flows to the upstream. A deny-on-presence policy (`default allow = true; allow = false if input.parsed_body.<forbidden>`) — the exact Rego shape the advisory describes — fails OPEN. The fix's own comment reasons only about `ContentLength == -1`; the oversized branch was never considered, and the added PoC test only covers small bodies. ### Affected code - `filters/openpolicyagent/openpolicyagent.go` `ExtractHttpBodyOptionally`: the `expectedSize <= maxBodyBytes` gate lets an oversized declared body fall through to `return req.Body, nil, func() {}, nil` (OPA sees an empty document). - Corroborated by Skipper's own unit test "Read body exhausting max bytes" (`{ "welcome": "world" }`, `maxBodySize: 5` → `bodyInPolicy: ""`). ### Steps to reproduce See attached `docker-compose.yml` (official `golang` image) + `setup.sh` + `exploit.sh`, which run a real Skipper proxy (`proxytest`) with a real OPA control plane (`opasdktest`), `WithMaxRequestBodyBytes(32)`, policy `allow = false if input.parsed_body.action == "delete"`, route `* -> opaAuthorizeRequestWithBody("test") -> upstream`: - `{"action":"delete"}` (19B ≤ 32) → **403** (denied). - `{"action":
Properties
- ghsa_id
- GHSA-8qqm-fp2q-v734
- severity
- high
- summary
- Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
- cvss_score
- 8.2
- cve_id
- GHSA-8qqm-fp2q-v734
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-07-17T21:49:48Z
- source_url
- https://github.com/advisories/GHSA-8qqm-fp2q-v734
- ghsa_updated
- 2026-07-21T09:31:01Z
Related Entities (3)
VULNERABLE_TO (1)
AFFECTS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph