Source: golang-github-google-cel-go
Version: 0.27.0+ds-6
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for golang-github-google-cel-go.

AFAIU, is this source package replaced by golang-cel-cel-go which
already contains the fix and should golang-github-google-cel-go be
removed? This is as well the reason to make a RC level issue here.

CVE-2026-83530[0]:
| A user could provide an expression whose string length is longer
| than the ParserExpressionSizeLimit() configured on the CEL
| environment, and a memory allocation would occur proportional to the
| size of the input before the limit would be checked / enforced.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-83530
    https://www.cve.org/CVERecord?id=CVE-2026-83530
[1] https://github.com/cel-expr/cel-go/pull/1302
[2] 
https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to