v1.19.1
2026-08-18T08:52:12Z•254ac292dd6c0f2089cc5d394d61c941253cd23f735c8267b044d8353ab3fc25
Compile APIGo standard libraryHTTP handlerOPAOpen Policy AgentRegoSQL injectioncryptographymemory leaksecurity update
What happened
Open Policy Agent releases v1.19.0–v1.19.1 include a fix for a SQL injection vulnerability in the Compile API, where caller-controlled dynamic field names could be emitted unquoted into SQL identifiers. Version 1.19.1 additionally updates the bundled Go toolchain to 1.26.6 to address multiple Go standard-library vulnerabilities affecting HTTP handling and cryptographic built-ins. Earlier releases also address a server memory leak and Go dependency vulnerabilities. No CVE identifiers are provided in the source.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- open_policy_agent_opa_releases
- Record identifier
- 254ac292dd6c0f2089cc5d394d61c941253cd23f735c8267b044d8353ab3fc25
- Enrichment time
- 2026-08-18T08:52:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.