GHSA-8qqm-fp2q-v734: Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
(updated )
A wrong policy can be an open door.
You have to check input.attributes.request.http.truncated_body in your policy.
References
Code Behaviors & Features
Detect and mitigate GHSA-8qqm-fp2q-v734 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →