CVE-2026-83530: Google Common Expression Language
Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.
A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced.
Affected products
- Google Common Expression Language: before 0.29.0 (fixed in 0.29.0)
Published 2026-09-09. Last modified 2026-09-23.