THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5gpm-rgj3-9q76 (high) — Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)

[GHSA] GHSA-5gpm-rgj3-9q76 (high) — Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)

medgithub_advisoriesPublished 2026-09-17

GHSA-5gpm-rgj3-9q76 Severity: high CVE: CVE-2026-86043

Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)

- **Affected component:** `filters/openpolicyagent/openpolicyagent.go` → `ExtractHttpBodyOptionally`; combined with `github.com/open-policy-agent/opa-envoy-plugin` `envoyauth/request.go` → `getParsedBody` / `checkIfH

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5gpm-rgj3-9q76