Vulnerability Report: GO-2025-3660

OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa

For detailed information about this vulnerability, visit https://github.com/open-policy-agent/opa/security/advisories/GHSA-6m8w-jc87-6cr7.

Affected Packages

  • Path
    Go Versions
    Symbols
  • before v1.4.0
    7 unexported affected symbols
    • Server.makeRego
    • Server.unversionedGetHealthWithPolicy
    • Server.v0QueryPath
    • baseHTTPListener.ListenAndServe
    • baseHTTPListener.ListenAndServeTLS
    • stringPathToDataRef
    • stringPathToRef

Aliases

References

Feedback

See anything missing or incorrect? Suggest an edit to this report.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL