Executive brief
CEL-Go is a library used to safely evaluate expressions in applications. A bug in the expression parser allows users to submit expressions larger than the configured size limit, causing the system to allocate memory proportional to the oversized input before the limit check occurs. This could lead to memory exhaustion and service disruption.
Technical details
The vulnerability is a bypass of the ParserExpressionSizeLimit() check in the CEL-Go parser. The root cause is that the size limit is enforced after memory allocation occurs in common.NewTextSource() during Env.Compile() and Env.Parse() calls, rather than before. An attacker providing an expression whose string length exceeds the configured limit can trigger allocation proportional to the input size, potentially causing denial of service through memory exhaustion. The fix moves the size limit enforcement to occur before source construction, preventing premature memory allocation.
Affected products
- CEL cel-go
Timeline
- 2026-09-09: disclosed
- 2026-05-19: patched: Fix merged in PR #1302