What is CVE-2026-65604?
CVE-2026-65604 is an incomplete fix for CVE-2026-50197 in Zscaler Skipper. It allows oversized request bodies to bypass OPA deny-on-presence policies, forwarding the full payload upstream when exceeding the maxBodyBytes limit. Affected Skipper users must apply the complete patch and review OPA policy configurations.
Azərbaycanca: CVE-2026-65604 Zscaler Skipper-də CVE-2026-50197 üçün natamam düzəlişdir. Böyük sorğu gövdələri OPA inkar siyasətlərini keçərək, `maxBodyBytes` limiti aşıldıqda upstream-ə tam ötürülür. Təsirlənən Skipper istifadəçiləri dərhal tam düzəliş tətbiq etməli və OPA siyasətlərini yoxlamalıdır.
FAQ2
Which previous vulnerability does CVE-2026-65604 represent an incomplete fix for in Zscaler Skipper?
CVE-2026-65604 is an incomplete fix for CVE-2026-50197 in Zscaler Skipper.
What actions should affected users take regarding CVE-2026-65604?
Affected Skipper users must apply the complete patch and review OPA policy configurations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.