What is CVE-2026-66144?
This CVE describes a denial of service vulnerability in Open Policy Agent (OPA) when remote policy references are manually retrieved via the API, allowing an attacker to overload the system with a huge policy. Users are advised to upgrade to version 3.2.3, which fixes the issue by enforcing a default maximum size limit.
Azərbaycanca: Bu CVE Open Policy Agent (OPA) versiyalarında API vasitəsilə uzaq siyasət arayışlarının əl ilə alınması zamanı baş verən "denial of service" hücumunu təsvir edir. Hücumçu böyük həcmli siyasəti yükləyərək sistemi sıradan çıxara bilər. İstifadəçilərə bu problemi həll edən 3.2.3 versiyasına keçmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What solution is recommended for OPA users to address CVE-2026-66144?
Upgrading to OPA version 3.2.3 is advised, as it fixes the issue.
During which operation does the CVE-2026-66144 vulnerability occur?
This vulnerability occurs when remote policy references are manually retrieved via the API in Open Policy Agent.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.