A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://github.com/cel-expr/cel-go/pull/1302 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 15:17
Updated : 2026-09-09 16:17
NVD link : CVE-2026-83530
Mitre link : CVE-2026-83530
CVE.ORG link : CVE-2026-83530
JSON object : View
Products Affected
No product.
CWE
CWE-789
Memory Allocation with Excessive Size Value
