Source: golang-github-google-cel-go Version: 0.27.0+ds-6 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for golang-github-google-cel-go. AFAIU, is this source package replaced by golang-cel-cel-go which already contains the fix and should golang-github-google-cel-go be removed? This is as well the reason to make a RC level issue here. CVE-2026-83530[0]: | A user could provide an expression whose string length is longer | than the ParserExpressionSizeLimit() configured on the CEL | environment, and a memory allocation would occur proportional to the | size of the input before the limit would be checked / enforced. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-83530 https://www.cve.org/CVERecord?id=CVE-2026-83530 [1] https://github.com/cel-expr/cel-go/pull/1302 [2] https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a Please adjust the affected versions in the BTS as needed. Regards, Salvatore

