v1.19.1

2026-08-18T08:52:12Z254ac292dd6c0f2089cc5d394d61c941253cd23f735c8267b044d8353ab3fc25
Compile APIGo standard libraryHTTP handlerOPAOpen Policy AgentRegoSQL injectioncryptographymemory leaksecurity update

What happened

Open Policy Agent releases v1.19.0–v1.19.1 include a fix for a SQL injection vulnerability in the Compile API, where caller-controlled dynamic field names could be emitted unquoted into SQL identifiers. Version 1.19.1 additionally updates the bundled Go toolchain to 1.26.6 to address multiple Go standard-library vulnerabilities affecting HTTP handling and cryptographic built-ins. Earlier releases also address a server memory leak and Go dependency vulnerabilities. No CVE identifiers are provided in the source.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
open_policy_agent_opa_releases
Record identifier
254ac292dd6c0f2089cc5d394d61c941253cd23f735c8267b044d8353ab3fc25
Enrichment time
2026-08-18T08:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.