Denial of Service Vulnerability in cel-rust Interpreter by Google
CVE-2025-62162

7.5HIGH

Key Information:

Vendor

Cel-rust

Status
Vendor
CVE Published:
10 October 2025

What is CVE-2025-62162?

The cel-rust interpreter, developed by Google, has a vulnerability that arises when certain malformed Common Expression Language (CEL) expressions are parsed. This flaw can lead to a denial of service condition, as the parsing process may enter a panic state, causing the interpreter to terminate unexpectedly. This is particularly concerning when the interpreter is exposed to untrusted inputs, such as those provided through APIs. Users are encouraged to upgrade to version 0.11.4 or later, which includes fixes for this issue. For further details, refer to the advisory and release notes linked below.

Affected Version(s)

cel-rust >= 0.10.0, < 0.11.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62162 : Denial of Service Vulnerability in cel-rust Interpreter by Google