- Package:
- src:golang-github-google-cel-go
- Source:
- src:golang-github-google-cel-go
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-07 08:13:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for golang-github-google-cel-go. AFAIU, is this source package replaced by golang-cel-cel-go which already contains the fix and should golang-github-google-cel-go be removed? This is as well the reason to make a RC level issue here. CVE-2026-83530[0]: | A user could provide an expression whose string length is longer | than the ParserExpressionSizeLimit() configured on the CEL | environment, and a memory allocation would occur proportional to the | size of the input before the limit would be checked / enforced. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-83530 https://www.cve.org/CVERecord?id=CVE-2026-83530 [1] https://github.com/cel-expr/cel-go/pull/1302 [2] https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a Please adjust the affected versions in the BTS as needed. Regards, Salvatore
superseded by golang-cel-cel-go but I'm not sure what needs to happen for that (it's tracked in #1146564). I'm also unsure about what to do in trixie. Incidentally, I've just uploaded 0.18.2+ds-5+deb13u1 for trixie-p-u without realizing about this CVE, sorry. If the patch applied cleanly to the trixie version (which I have not checked yet), we could either ask the SRM to cancel 0.18.2+ds-5+deb13u1, or maybe just make another release on top of that versioned +deb13u2. Cc: Simon for advice. Thanks.
I confirm that the patch does *not* apply cleanly. Took it from this URL: https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a.patch and this is how it goes on top of a tree with debian/patches already applied: $ cat ../CVE-2026-83530.patch | patch -p1 patching file cel/cel_test.go Hunk #1 succeeded at 20 with fuzz 2 (offset -2 lines). Hunk #2 succeeded at 2873 (offset -1036 lines). patching file cel/env.go Hunk #1 succeeded at 254 (offset -182 lines). Hunk #2 succeeded at 272 (offset -182 lines). Hunk #3 succeeded at 444 (offset -219 lines). patching file common/runes/buffer.go Hunk #2 FAILED at 114. Hunk #3 FAILED at 196. Hunk #4 FAILED at 223. Hunk #5 FAILED at 239. 4 out of 5 hunks FAILED -- saving rejects to file common/runes/buffer.go.rej patching file common/runes/buffer_test.go patching file common/source.go Hunk #1 succeeded at 77 (offset 3 lines). Hunk #2 succeeded at 100 (offset 9 lines). patching file common/source_test.go Somebody who know golang better than me would have to look at this. Thanks.
Hi Santiago, There are two different projects maintained in paralle from upsteam. The patch you applied seems was from https://github.com/cel-expr/cel-go Correct repo for this package should be https://github.com/google/cel-go The correct patch for github.com/google/cel-go is this one: https://github.com/google/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a You may also simply update this golang-github-google-cel-go package to newer upstream version (>= v0.29.0) which included this fix. Best regards,
Thanks for the pointer, I'll see if I can manage it myself. (Yesterday I was in the middle of an archive rebuild for glibc in experimental). Well, but that will not fix the CVE problem in trixie, which is also my concern here. Thanks.
Arthur: While we are at it, would you be willing to upgrade the package to >= 0.29.0 in unstable, while I still keep looking at how to backport the fix to trixie? Thanks.
Ok, the patch applies cleanly in unstable, I'm going to make a team upload first to fix the CVE in unstable. (After that, anybody feel free to upgrade the package, I'm usually hesitant to do that because I prefer to work on the rearguard). Thanks.
You may also make an update in another branch and then run salsa-ci test with reverse dependency rebuilds. If there is nothing broken, it's safe to upload the new version instead. It's probably less work than apply the patch. :) Best regards,
Ok, for the record: The right patch applies cleanly but it produces this build error: # github.com/google/cel-go/cel src/github.com/google/cel-go/cel/env.go:399:12: e.limits undefined (type *Env has no field or method limits) src/github.com/google/cel-go/cel/env.go:399:19: undefined: limitCodePointSize src/github.com/google/cel-go/cel/env.go:416:15: undefined: ErrorAsIssues src/github.com/google/cel-go/cel/env.go:619:15: undefined: ErrorAsIssues So upgrading to the new version looks indeed the preferred course of action here. Thanks.
owner 1147513 ! thanks Hi. I will take care of upgrading the package this afternoon. Three of its reverse build-dependencies fail to build, but they already failed before, so that does not count as a regression. Additionally, golang-github-newrelic-go-agent now fails to build randomly, but on the other side, it has a new upstream version available. So, I think that's a more than acceptable tradeoff while fixing a CVE. (Thanks, Andrew, for your encouragement :-) Thanks.
Hi Santiago, Still need help here updating the package in unstable? Regards, Arthur
Actually... yes. After updating the package in my private fork, the package does not build in Salsa CI because of some test failures. So, I've just pushed what I have, with UNRELEASED in the changelog, so that you can continue where I left. (Just wait a little until the pipeline finish and you will see the failures). Thanks a lot.
Hmm, I wonder why in earth are we trying to fix this package at all when it has already been renamed to "golang-cel-cel-go" according to #1146564 ? Looks like we all forgot about this little detail, or we still want to update for some reason which I don't know? My main concern was fixing the CVE in trixie after 0.18.2+ds-5+deb13u1 (i.e. new upload versioned +deb13u2), if such thing is feasible. Thanks.
I agree, I think we should just RM it. Let me check packages still with B-D on the old version. Regards, Arthur
build-rdeps --distribution unstable golang-github-google-cel-go-dev Reverse Build-depends in unstable/main: --------------------------------------- caddy chezmoi golang-github-betterleaks-betterleaks golang-google-grpc prometheus-blackbox-exporter Found a total of 5 reverse build-depend(s) for golang-github-google-cel-go-dev.
Hi Andrew, Are you able to push the upstream tag from your last upload of golang-github-betterleaks-betterleaks to Salsa please? - https://salsa.debian.org/go-team/packages/golang-github-betterleaks-betterleaks - https://tracker.debian.org/pkg/golang-github-betterleaks-betterleaks Error I'm getting: gbp buildpackage gbp:error: upstream/1.4.1 is not a valid treeish
Thank for catching that. Pushed. And there is a new release of betterleaks that doesn't require cel-go at all. Best regards,
New upstream version v2.11.5 switched to use cel.dev/cel-go v0.32.0: https://github.com/caddyserver/caddy/blob/v2.11.5/go.mod#L6 The latest version uploaded a few days ago doesn't deps on github.com/google/cel-go. https://forgejo.debian.net/chezmoi/chezmoi/src/branch/debian/go.mod Newer upstream version v1.6.0 doesn't deps on github.com/google/cel-go: https://github.com/betterleaks/betterleaks/blob/v1.6.0/go.mod ^ Be careful! This needs to update together with golang-google-api and golang-google-cloud together. Please check the compatiable upstream versions first, and then check reverse-deps of these 3 packages before bump to newer version. Upstream git HEAD still using github.com/google/cel-go v0.30.0: https://github.com/prometheus/blackbox_exporter/blob/master/go.mod#L9 So the main blocker for remove this in unstable will be golang-google-grpc and prometheus-blackbox-exporter. But when I check the reverse-deps on trixie I found: $ build-rdeps golang-github-google-cel-go-dev Reverse Build-depends in stable/main: ------------------------------------- alertmanager-irc-relay aptly balboa caddy certstream-server-go cloudsql-proxy containerd cosign crowdsec crowdsec-custom-bouncer crowdsec-firewall-bouncer distrobuilder dnscrypt-proxy docker-buildx docker-compose docker-libkv docker.io etcd fastnetmon fever gh gitaly gitlab-shell gitsign gittuf go-containerregistry gobgp golang-collectd golang-entgo-ent golang-github-anacrolix-chansync golang-github-anacrolix-dms golang-github-anacrolix-ffprobe golang-github-anacrolix-missinggo golang-github-anacrolix-sync golang-github-anacrolix-tagflag golang-github-awslabs-soci-snapshotter golang-github-canonical-candid golang-github-checkpoint-restore-checkpointctl golang-github-containerd-errdefs golang-github-containerd-imgcrypt golang-github-containerd-nri golang-github-containerd-nydus-snapshotter golang-github-containerd-stargz-snapshotter golang-github-containers-buildah golang-github-containers-common golang-github-containers-image golang-github-containers-ocicrypt golang-github-containers-psgo golang-github-containers-storage golang-github-crc-org-crc golang-github-crowdsecurity-go-cs-bouncer golang-github-docker-leadership golang-github-expediadotcom-haystack-client-go golang-github-francoispqt-gojay golang-github-fsouza-go-dockerclient golang-github-getsentry-sentry-go golang-github-go-kit-kit golang-github-go-llsqlite-crawshaw golang-github-go-openapi-runtime golang-github-google-cel-go golang-github-google-s2a-go golang-github-googleapis-gax-go golang-github-googlecloudplatform-guest-logging-go golang-github-graph-gophers-graphql-go golang-github-gravitational-trace golang-github-grpc-ecosystem-go-grpc-middleware golang-github-grpc-ecosystem-go-grpc-prometheus golang-github-grpc-ecosystem-grpc-gateway golang-github-grpc-ecosystem-grpc-opentracing golang-github-hashicorp-go-discover golang-github-hashicorp-go-plugin golang-github-henrybear327-go-proton-api golang-github-henrybear327-proton-api-bridge golang-github-hugelgupf-p9 golang-github-jacobsa-gcloud golang-github-jedisct1-go-hpke-compact golang-github-juju-persistent-cookiejar golang-github-katalix-go-l2tp golang-github-kubernetes-cri-api golang-github-lightstep-lightstep-tracer-common golang-github-lucas-clemente-quic-go golang-github-mendersoftware-mender-artifact golang-github-micromdm-scep golang-github-minio-colorjson golang-github-minio-pkg golang-github-mostynb-go-grpc-compression golang-github-mudler-docker-companion golang-github-newrelic-go-agent golang-github-openfga-go-sdk golang-github-openpubkey-openpubkey golang-github-openshift-imagebuilder golang-github-opentracing-contrib-go-grpc golang-github-openzipkin-zipkin-go golang-github-optiopay-kafka golang-github-powerman-check golang-github-rootless-containers-bypass4netns golang-github-samalba-dockerclient golang-github-seandolphin-bqschema golang-github-sercand-kuberesolver golang-github-shurcool-githubv4 golang-github-shurcool-graphql golang-github-sigstore-fulcio golang-github-sigstore-protobuf-specs golang-github-sigstore-sigstore golang-github-sigstore-timestamp-authority golang-github-smallstep-certificates golang-github-spiffe-go-spiffe golang-github-sylabs-sif golang-github-theupdateframework-go-tuf golang-github-tink-crypto-tink-go-gcpkms golang-github-tonistiigi-fsutil golang-github-viant-assertly golang-github-viant-toolbox golang-github-vulcand-predicate golang-github-xenolf-lego golang-github-xordataexchange-crypt golang-github-zitadel-oidc golang-gitlab-gitlab-org-labkit golang-go.opencensus golang-go.uber-zap golang-go4 golang-gocloud golang-gogottrpc golang-google-api golang-google-cloud golang-google-genproto golang-google-grpc golang-k8s-component-base golang-k8s-kms golang-opentelemetry-contrib golang-opentelemetry-otel golang-opentelemetry-proto golang-step-linkedca golang-v2ray-core google-guest-agent hugo ignition in-toto-golang incus influxdb kubernetes litetlog lxd mgmt minio-client mirrorbits mtail nextcloud-spreed-signaling nncp notary ntfy oci-seccomp-bpf-hook open-vm-tools opensnitch opkssh podman prometheus prometheus-alertmanager prometheus-blackbox-exporter prometheus-hacluster-exporter prometheus-mqtt-exporter prometheus-postfix-exporter prometheus-pushgateway prometheus-sql-exporter protobuild rclone receptor rekor restic riseup-vpn shoelaces sigstore-go skeema skopeo stenographer syncthing trillian victoriametrics vip-manager vip-manager2 yggdrasil Found a total of 181 reverse build-depend(s) for golang-github-google-cel-go-dev. It seems we don't need to hurry to remove it in unstable now as we cannot resolve all the issues in trixie for it. Best regards,