#1147513 golang-github-google-cel-go: CVE-2026-83530

#1147513#5
Date:
2026-09-12 15:07:07 UTC
From:
To:
Hi,

The following vulnerability was published for golang-github-google-cel-go.

AFAIU, is this source package replaced by golang-cel-cel-go which
already contains the fix and should golang-github-google-cel-go be
removed? This is as well the reason to make a RC level issue here.

CVE-2026-83530[0]:
| A user could provide an expression whose string length is longer
| than the ParserExpressionSizeLimit() configured on the CEL
| environment, and a memory allocation would occur proportional to the
| size of the input before the limit would be checked / enforced.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-83530
https://www.cve.org/CVERecord?id=CVE-2026-83530
[1] https://github.com/cel-expr/cel-go/pull/1302
[2] https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1147513#10
Date:
2026-09-14 23:29:47 UTC
From:
To:
superseded by golang-cel-cel-go but I'm not sure what needs to happen
for that (it's tracked in #1146564).

I'm also unsure about what to do in trixie. Incidentally, I've just
uploaded 0.18.2+ds-5+deb13u1 for trixie-p-u without realizing about
this CVE, sorry.

If the patch applied cleanly to the trixie version (which I have not checked yet),
we could either ask the SRM to cancel 0.18.2+ds-5+deb13u1, or maybe
just make another release on top of that versioned +deb13u2.

Cc: Simon for advice.

Thanks.

#1147513#15
Date:
2026-09-14 23:43:28 UTC
From:
To:
I confirm that the patch does *not* apply cleanly.
Took it from this URL:

https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a.patch

and this is how it goes on top of a tree with debian/patches already applied:

$ cat ../CVE-2026-83530.patch | patch -p1
patching file cel/cel_test.go
Hunk #1 succeeded at 20 with fuzz 2 (offset -2 lines).
Hunk #2 succeeded at 2873 (offset -1036 lines).
patching file cel/env.go
Hunk #1 succeeded at 254 (offset -182 lines).
Hunk #2 succeeded at 272 (offset -182 lines).
Hunk #3 succeeded at 444 (offset -219 lines).
patching file common/runes/buffer.go
Hunk #2 FAILED at 114.
Hunk #3 FAILED at 196.
Hunk #4 FAILED at 223.
Hunk #5 FAILED at 239.
4 out of 5 hunks FAILED -- saving rejects to file common/runes/buffer.go.rej
patching file common/runes/buffer_test.go
patching file common/source.go
Hunk #1 succeeded at 77 (offset 3 lines).
Hunk #2 succeeded at 100 (offset 9 lines).
patching file common/source_test.go

Somebody who know golang better than me would have to look at this.

Thanks.

#1147513#20
Date:
2026-10-05 08:15:25 UTC
From:
To:
Hi Santiago,

There are two different projects maintained in paralle from upsteam.

The patch you applied seems was from https://github.com/cel-expr/cel-go
Correct repo for this package should be https://github.com/google/cel-go

The correct patch for github.com/google/cel-go is this one:
https://github.com/google/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a

You may also simply update this golang-github-google-cel-go package to
newer upstream version (>= v0.29.0) which included this fix.

Best regards,

#1147513#25
Date:
2026-10-06 11:36:45 UTC
From:
To:
Thanks for the pointer, I'll see if I can manage it myself.
(Yesterday I was in the middle of an archive rebuild for glibc in experimental).

Well, but that will not fix the CVE problem in trixie, which is also
my concern here.

Thanks.

#1147513#30
Date:
2026-10-06 11:43:11 UTC
From:
To:
Arthur: While we are at it, would you be willing to upgrade the
package to >= 0.29.0 in unstable, while I still keep looking at how to
backport the fix to trixie?

Thanks.

#1147513#35
Date:
2026-10-06 12:15:58 UTC
From:
To:
Ok, the patch applies cleanly in unstable, I'm going to make a team upload
first to fix the CVE in unstable.

(After that, anybody feel free to upgrade the package, I'm usually
hesitant to do that because I prefer to work on the rearguard).

Thanks.

#1147513#40
Date:
2026-10-06 12:32:15 UTC
From:
To:
You may also make an update in another branch and then run salsa-ci
test with reverse dependency rebuilds. If there is nothing broken,
it's safe to upload the new version instead. It's probably less work
than apply the patch. :)

Best regards,

#1147513#45
Date:
2026-10-06 12:39:54 UTC
From:
To:
Ok, for the record:

The right patch applies cleanly but it produces this build error:

# github.com/google/cel-go/cel
src/github.com/google/cel-go/cel/env.go:399:12: e.limits undefined (type *Env has no field or method limits)
src/github.com/google/cel-go/cel/env.go:399:19: undefined: limitCodePointSize
src/github.com/google/cel-go/cel/env.go:416:15: undefined: ErrorAsIssues
src/github.com/google/cel-go/cel/env.go:619:15: undefined: ErrorAsIssues

So upgrading to the new version looks indeed the preferred course of
action here.

Thanks.

#1147513#50
Date:
2026-10-06 13:56:26 UTC
From:
To:
owner 1147513 !
thanks

Hi.

I will take care of upgrading the package this afternoon.

Three of its reverse build-dependencies fail to build, but they
already failed before, so that does not count as a regression.

Additionally, golang-github-newrelic-go-agent now fails to build randomly,
but on the other side, it has a new upstream version available.

So, I think that's a more than acceptable tradeoff while fixing a CVE.

(Thanks, Andrew, for your encouragement :-)

Thanks.

#1147513#57
Date:
2026-10-06 14:55:40 UTC
From:
To:
Hi Santiago,

Still need help here updating the package in unstable?

Regards,
Arthur

#1147513#62
Date:
2026-10-06 15:36:47 UTC
From:
To:
Actually... yes.

After updating the package in my private fork, the package does not build
in Salsa CI because of some test failures.

So, I've just pushed what I have, with UNRELEASED in the changelog,
so that you can continue where I left.

(Just wait a little until the pipeline finish and you will see the failures).

Thanks a lot.

#1147513#69
Date:
2026-10-06 15:56:31 UTC
From:
To:
Hmm, I wonder why in earth are we trying to fix this package at all
when it has already been renamed to "golang-cel-cel-go" according to #1146564 ?

Looks like we all forgot about this little detail, or we still want
to update for some reason which I don't know?

My main concern was fixing the CVE in trixie after 0.18.2+ds-5+deb13u1
(i.e. new upload versioned +deb13u2), if such thing is feasible.

Thanks.

#1147513#74
Date:
2026-10-06 16:26:56 UTC
From:
To:
I agree, I think we should just RM it.

Let me check packages still with B-D on the old version.

Regards,
Arthur

#1147513#79
Date:
2026-10-06 16:31:16 UTC
From:
To:
build-rdeps --distribution unstable golang-github-google-cel-go-dev
Reverse Build-depends in unstable/main:
---------------------------------------

caddy
chezmoi
golang-github-betterleaks-betterleaks
golang-google-grpc
prometheus-blackbox-exporter

Found a total of 5 reverse build-depend(s) for
golang-github-google-cel-go-dev.

#1147513#84
Date:
2026-10-06 23:01:43 UTC
From:
To:
Hi Andrew,

Are you able to push the upstream tag from your last upload of
golang-github-betterleaks-betterleaks to Salsa please?

-
https://salsa.debian.org/go-team/packages/golang-github-betterleaks-betterleaks
- https://tracker.debian.org/pkg/golang-github-betterleaks-betterleaks

Error I'm getting:

gbp buildpackage
gbp:error: upstream/1.4.1 is not a valid treeish

#1147513#94
Date:
2026-10-07 07:53:43 UTC
From:
To:
Thank for catching that. Pushed.

And there is a new release of betterleaks that doesn't require cel-go at all.

Best regards,

#1147513#99
Date:
2026-10-07 08:10:09 UTC
From:
To:
New upstream version v2.11.5 switched to use cel.dev/cel-go v0.32.0:
https://github.com/caddyserver/caddy/blob/v2.11.5/go.mod#L6
The latest version uploaded a few days ago doesn't deps on
github.com/google/cel-go.
https://forgejo.debian.net/chezmoi/chezmoi/src/branch/debian/go.mod
Newer upstream version v1.6.0 doesn't deps on github.com/google/cel-go:
https://github.com/betterleaks/betterleaks/blob/v1.6.0/go.mod
^ Be careful! This needs to update together with golang-google-api and
golang-google-cloud together. Please check the compatiable upstream
versions first, and then check reverse-deps of these 3 packages before
bump to newer version.
Upstream git HEAD still using github.com/google/cel-go v0.30.0:
https://github.com/prometheus/blackbox_exporter/blob/master/go.mod#L9

So the main blocker for remove this in unstable will be
golang-google-grpc and prometheus-blackbox-exporter.

But when I check the reverse-deps on trixie I found:
$ build-rdeps golang-github-google-cel-go-dev
Reverse Build-depends in stable/main:
-------------------------------------

alertmanager-irc-relay
aptly
balboa
caddy
certstream-server-go
cloudsql-proxy
containerd
cosign
crowdsec
crowdsec-custom-bouncer
crowdsec-firewall-bouncer
distrobuilder
dnscrypt-proxy
docker-buildx
docker-compose
docker-libkv
docker.io
etcd
fastnetmon
fever
gh
gitaly
gitlab-shell
gitsign
gittuf
go-containerregistry
gobgp
golang-collectd
golang-entgo-ent
golang-github-anacrolix-chansync
golang-github-anacrolix-dms
golang-github-anacrolix-ffprobe
golang-github-anacrolix-missinggo
golang-github-anacrolix-sync
golang-github-anacrolix-tagflag
golang-github-awslabs-soci-snapshotter
golang-github-canonical-candid
golang-github-checkpoint-restore-checkpointctl
golang-github-containerd-errdefs
golang-github-containerd-imgcrypt
golang-github-containerd-nri
golang-github-containerd-nydus-snapshotter
golang-github-containerd-stargz-snapshotter
golang-github-containers-buildah
golang-github-containers-common
golang-github-containers-image
golang-github-containers-ocicrypt
golang-github-containers-psgo
golang-github-containers-storage
golang-github-crc-org-crc
golang-github-crowdsecurity-go-cs-bouncer
golang-github-docker-leadership
golang-github-expediadotcom-haystack-client-go
golang-github-francoispqt-gojay
golang-github-fsouza-go-dockerclient
golang-github-getsentry-sentry-go
golang-github-go-kit-kit
golang-github-go-llsqlite-crawshaw
golang-github-go-openapi-runtime
golang-github-google-cel-go
golang-github-google-s2a-go
golang-github-googleapis-gax-go
golang-github-googlecloudplatform-guest-logging-go
golang-github-graph-gophers-graphql-go
golang-github-gravitational-trace
golang-github-grpc-ecosystem-go-grpc-middleware
golang-github-grpc-ecosystem-go-grpc-prometheus
golang-github-grpc-ecosystem-grpc-gateway
golang-github-grpc-ecosystem-grpc-opentracing
golang-github-hashicorp-go-discover
golang-github-hashicorp-go-plugin
golang-github-henrybear327-go-proton-api
golang-github-henrybear327-proton-api-bridge
golang-github-hugelgupf-p9
golang-github-jacobsa-gcloud
golang-github-jedisct1-go-hpke-compact
golang-github-juju-persistent-cookiejar
golang-github-katalix-go-l2tp
golang-github-kubernetes-cri-api
golang-github-lightstep-lightstep-tracer-common
golang-github-lucas-clemente-quic-go
golang-github-mendersoftware-mender-artifact
golang-github-micromdm-scep
golang-github-minio-colorjson
golang-github-minio-pkg
golang-github-mostynb-go-grpc-compression
golang-github-mudler-docker-companion
golang-github-newrelic-go-agent
golang-github-openfga-go-sdk
golang-github-openpubkey-openpubkey
golang-github-openshift-imagebuilder
golang-github-opentracing-contrib-go-grpc
golang-github-openzipkin-zipkin-go
golang-github-optiopay-kafka
golang-github-powerman-check
golang-github-rootless-containers-bypass4netns
golang-github-samalba-dockerclient
golang-github-seandolphin-bqschema
golang-github-sercand-kuberesolver
golang-github-shurcool-githubv4
golang-github-shurcool-graphql
golang-github-sigstore-fulcio
golang-github-sigstore-protobuf-specs
golang-github-sigstore-sigstore
golang-github-sigstore-timestamp-authority
golang-github-smallstep-certificates
golang-github-spiffe-go-spiffe
golang-github-sylabs-sif
golang-github-theupdateframework-go-tuf
golang-github-tink-crypto-tink-go-gcpkms
golang-github-tonistiigi-fsutil
golang-github-viant-assertly
golang-github-viant-toolbox
golang-github-vulcand-predicate
golang-github-xenolf-lego
golang-github-xordataexchange-crypt
golang-github-zitadel-oidc
golang-gitlab-gitlab-org-labkit
golang-go.opencensus
golang-go.uber-zap
golang-go4
golang-gocloud
golang-gogottrpc
golang-google-api
golang-google-cloud
golang-google-genproto
golang-google-grpc
golang-k8s-component-base
golang-k8s-kms
golang-opentelemetry-contrib
golang-opentelemetry-otel
golang-opentelemetry-proto
golang-step-linkedca
golang-v2ray-core
google-guest-agent
hugo
ignition
in-toto-golang
incus
influxdb
kubernetes
litetlog
lxd
mgmt
minio-client
mirrorbits
mtail
nextcloud-spreed-signaling
nncp
notary
ntfy
oci-seccomp-bpf-hook
open-vm-tools
opensnitch
opkssh
podman
prometheus
prometheus-alertmanager
prometheus-blackbox-exporter
prometheus-hacluster-exporter
prometheus-mqtt-exporter
prometheus-postfix-exporter
prometheus-pushgateway
prometheus-sql-exporter
protobuild
rclone
receptor
rekor
restic
riseup-vpn
shoelaces
sigstore-go
skeema
skopeo
stenographer
syncthing
trillian
victoriametrics
vip-manager
vip-manager2
yggdrasil

Found a total of 181 reverse build-depend(s) for
golang-github-google-cel-go-dev.

It seems we don't need to hurry to remove it in unstable now as we
cannot resolve all the issues in trixie for it.

Best regards,