Denial of Service Vulnerability in cel-rust Interpreter by Google
CVE-2025-62162
7.5HIGH
What is CVE-2025-62162?
The cel-rust interpreter, developed by Google, has a vulnerability that arises when certain malformed Common Expression Language (CEL) expressions are parsed. This flaw can lead to a denial of service condition, as the parsing process may enter a panic state, causing the interpreter to terminate unexpectedly. This is particularly concerning when the interpreter is exposed to untrusted inputs, such as those provided through APIs. Users are encouraged to upgrade to version 0.11.4 or later, which includes fixes for this issue. For further details, refer to the advisory and release notes linked below.
Affected Version(s)
cel-rust >= 0.10.0, < 0.11.4