Prepare v1.20.1 release
2026-08-28T08:52:13Z•483f86f1abff35efc510df7686752866d32f12ad188d4659a4d6c8edbd0d299f
Compile APIGo standard-library vulnerabilitiesHTTP handlerJSON SchemaOPAOpen Policy AgentRegoSQL injectioncryptographydependency updatememory leaksecurity release
What happened
Open Policy Agent releases include security-relevant fixes. OPA v1.19.0 fixed a SQL injection vector in the Compile API caused by unescaped, caller-controlled SQL identifier fields. Patch releases v1.19.1 and v1.17.1 updated the Go toolchain to address multiple Go standard-library vulnerabilities affecting OPA's HTTP handler and cryptographic built-ins. Earlier v1.18.1 fixed a server memory leak, while v1.20.0 added restrictions on remote JSON Schema reference fetching. Organizations using affected OPA versions should upgrade to the latest supported release and review Compile API exposure and,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- open_policy_agent_opa_releases
- Record identifier
- 483f86f1abff35efc510df7686752866d32f12ad188d4659a4d6c8edbd0d299f
- Enrichment time
- 2026-08-28T08:52:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.