v1.20.2
2026-09-08T08:52:14Z•1aef8378ff4937a04147521da2c2ba824e101313d3c7c86933e8e67f75e5a164
Compile APIGo standard library vulnerabilitiesOPAOpen Policy AgentRegoSQL injectiondependency updatememory leakparser regressionpolicy enginesecurity patch
What happened
Open Policy Agent releases v1.17.1 through v1.20.2 include security and reliability fixes. OPA v1.19.0 fixes a SQL injection vector in the Compile API caused by unquoted caller-controlled SQL identifier fields. Earlier patch releases update Go to address multiple standard-library vulnerabilities, fix a server memory leak, and correct parser, formatter, numeric-comparison, and other regressions. Organizations using OPA should prioritize upgrading versions affected by the Compile API SQL injection issue and review custom builds for embedded Go runtime updates.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- open_policy_agent_opa_releases
- Record identifier
- 1aef8378ff4937a04147521da2c2ba824e101313d3c7c86933e8e67f75e5a164
- Enrichment time
- 2026-09-08T08:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.