CVE-2026-83530
Analyzed Analyzed - Analysis Complete

Memory Exhaustion in CEL Expression Parser

Vulnerability report for CVE-2026-83530, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-23

Assigner: Google Inc.

Description

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-23
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google common_expression_language to 0.29.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a user to provide an expression string longer than the configured ParserExpressionSizeLimit in the CEL environment. The parser first allocates memory proportional to the input size before checking the limit, causing unnecessary memory consumption and potential denial-of-service conditions.

Detection Guidance

Monitor for excessive memory usage during CEL expression parsing. Check for processes using cel-go that consume unusually high memory when processing large inputs. Use system monitoring tools like top, htop, or ps to observe memory spikes during parsing operations.

Impact Analysis

An attacker could exploit this to consume excessive memory by submitting oversized expressions, leading to system slowdowns or crashes. This may result in denial-of-service attacks affecting availability of services using the cel-go library.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling denial-of-service conditions through excessive memory consumption. Uncontrolled resource consumption (CWE-400) may lead to system instability or crashes, which could disrupt data processing or access controls required by these regulations.

Mitigation Strategies

Update the cel-go library to the patched version that enforces ParserExpressionSizeLimit before memory allocation. Review and adjust ParserExpressionSizeLimit configurations to appropriate values for your environment. Test the update in a non-production environment before full deployment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83530. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart