v1.20.1
2026-08-29T08:52:12Z•b778998842450e30272eeb00dae38381d7bcb81a95456438fbf790fc045fc147
Compile APIGo standard library vulnerabilitiesHTTP handlerOPAOpen Policy AgentRegoSQL injectioncryptographymemory leakpolicy enginereleasesecurity update
What happened
Open Policy Agent releases v1.17.0 through v1.20.1 include security-relevant fixes and maintenance updates. OPA v1.19.0 fixes a SQL injection vector in the Compile API when caller-controlled dynamic policy keys were emitted as SQL identifiers. OPA v1.19.1 and v1.17.1 update the embedded Go toolchain to address multiple Go standard-library vulnerabilities affecting HTTP and cryptographic functionality. OPA v1.18.1 fixes a server memory leak, while v1.20.1 corrects a numeric comparison regression. No CVE identifiers are provided in the release notes.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- open_policy_agent_opa_releases
- Record identifier
- b778998842450e30272eeb00dae38381d7bcb81a95456438fbf790fc045fc147
- Enrichment time
- 2026-08-29T08:52:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.