Skip to content

Correct the patched version of GHSA-gcjh-h69q-9w9g (cel-go) to 0.30.0 - #10090

Open
khamon wants to merge 1 commit into
github:khamon/advisory-improvement-10090from
khamon:khamon-GHSA-gcjh-h69q-9w9g
Open

khamon wants to merge 1 commit into
github:khamon/advisory-improvement-10090from
khamon:khamon-GHSA-gcjh-h69q-9w9g

Conversation

@khamon

@khamon khamon commented Oct 1, 2026

Copy link
Copy Markdown

The affected range and patched version of this advisory do not match the maintainers' advisory or the code.

What this changes

  • fixed: 0.29.0 to 0.30.0
  • last_known_affected_version_range: <= 0.28.1 to <= 0.29.2

Why

The repository advisory published by cel-expr/cel-go for this GHSA lists the vulnerable range as v0.22.0 through v0.29.2 and the patched version as v0.30.0:
GHSA-gcjh-h69q-9w9g

The Go vulnerability database entry for the same advisory, GO-2026-6094, also gives 0.30.0 as the fixed version:
https://pkg.go.dev/vuln/GO-2026-6094

The code agrees. ext/native.go is byte-identical at v0.28.0, v0.28.1, v0.29.0 and v0.29.2 (git blob c30f26ad3122). The fix, the isSkippedFieldName check that skips fields tagged json:"-", first appears at v0.30.0 (blob d9f5fab0decc).

As the entry stands, a project that upgrades to 0.29.x has its Dependabot alert closed while the vulnerable code is still present.

@github-actions
github-actions Bot changed the base branch from main to khamon/advisory-improvement-10090 October 1, 2026 20:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant