Executive brief
A vulnerability in the Common Expression Language (CEL) library for Go allows users to access private data fields that were intended to be hidden. When developers use specific settings to map Go data structures to CEL, fields marked to be skipped (using the standard JSON "-" tag) are instead exposed under a literal name. This could allow an attacker to read sensitive internal information, such as secrets or tokens, that the application developer never intended to make public.
Technical details
The `ext.NativeTypes(ParseStructTag("json"))` function in cel-go does not correctly implement the `encoding/json` skip directive (`json:"-"`). Instead of omitting these fields, the `fieldNameByTag` helper registers them in the CEL type system under the literal name `"-"`. An attacker capable of submitting CEL expressions can retrieve these private values using indexer access, such as `dyn(obj)["-"]`. Furthermore, `newNativeTypes` recursively registers all nested structs, potentially exposing sensitive fields in third-party dependencies. The issue also affects `ConvertToNative` operations, where skipped fields appear in the resulting JSON-like output. The vulnerability is addressed in version 0.29.0.
Affected products
- Google cel-go >= 0.22.0, <= 0.28.1
Timeline
- 2026-07-23: disclosed: Initial disclosure on GitHub Advisories
- 2026-07-24: advisory: Advisory updated
- 2026-07-24: patched: Fixed in version 0.29.0