Hi,
The following vulnerability was published for golang-github-google-cel-go.
AFAIU, is this source package replaced by golang-cel-cel-go which
already contains the fix and should golang-github-google-cel-go be
removed? This is as well the reason to make a RC level issue here.
CVE-2026-83530[0]:
| A user could provide an expression whose string length is longer
| than the ParserExpressionSizeLimit() configured on the CEL
| environment, and a memory allocation would occur proportional to the
| size of the input before the limit would be checked / enforced.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-83530
https://www.cve.org/CVERecord?id=CVE-2026-83530
[1] https://github.com/cel-expr/cel-go/pull/1302
[2] https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore