#1147513 golang-github-google-cel-go: CVE-2026-83530

#1147513#5
Date:
2026-09-12 15:07:07 UTC
From:
To:
Hi,

The following vulnerability was published for golang-github-google-cel-go.

AFAIU, is this source package replaced by golang-cel-cel-go which
already contains the fix and should golang-github-google-cel-go be
removed? This is as well the reason to make a RC level issue here.

CVE-2026-83530[0]:
| A user could provide an expression whose string length is longer
| than the ParserExpressionSizeLimit() configured on the CEL
| environment, and a memory allocation would occur proportional to the
| size of the input before the limit would be checked / enforced.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-83530
https://www.cve.org/CVERecord?id=CVE-2026-83530
[1] https://github.com/cel-expr/cel-go/pull/1302
[2] https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore