{"id":"DEBIAN-CVE-2026-83530","details":"A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced.","modified":"2026-09-24T09:00:15.070621183Z","published":"2026-09-09T15:17:12.123Z","upstream":["CVE-2026-83530"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-83530"}],"affected":[{"package":{"name":"golang-cel-cel-go","ecosystem":"Debian:14","purl":"pkg:deb/debian/golang-cel-cel-go?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.32.0+ds-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-83530.json"}},{"package":{"name":"golang-github-google-cel-go","ecosystem":"Debian:13","purl":"pkg:deb/debian/golang-github-google-cel-go?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.18.2+ds-5","0.18.2+ds-6","0.18.2+ds-7","0.27.0+ds-1","0.27.0+ds-1~exp1","0.27.0+ds-2","0.27.0+ds-3","0.27.0+ds-3~bpo13+1","0.27.0+ds-3~bpo13+2","0.27.0+ds-4","0.27.0+ds-5","0.27.0+ds-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-83530.json"}},{"package":{"name":"golang-github-google-cel-go","ecosystem":"Debian:14","purl":"pkg:deb/debian/golang-github-google-cel-go?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.18.2+ds-5","0.18.2+ds-6","0.18.2+ds-7","0.27.0+ds-1","0.27.0+ds-1~exp1","0.27.0+ds-2","0.27.0+ds-3","0.27.0+ds-3~bpo13+1","0.27.0+ds-3~bpo13+2","0.27.0+ds-4","0.27.0+ds-5","0.27.0+ds-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-83530.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}