Skip to content

fix: cap format string precision to prevent memory exhaustion#1292

Merged
TristonianJones merged 4 commits intogoogle:masterfrom
Flo354:fix/format-precision-bomb
Apr 6, 2026
Merged

fix: cap format string precision to prevent memory exhaustion#1292
TristonianJones merged 4 commits intogoogle:masterfrom
Flo354:fix/format-precision-bomb

Conversation

@Flo354
Copy link
Copy Markdown
Contributor

@Flo354 Flo354 commented Mar 23, 2026

parsePrecision() in ext/formatting.go and parsePrecisionV2() in ext/formatting_v2.go accept unbounded precision values from format strings. An expression like "%.9999999f".format([3.14]) causes fmt.Sprintf to allocate a string proportional to the precision value. At cost 501, a single expression can allocate 792MB.

The fix adds a maxPrecision constant (1000) and rejects precision values exceeding it. This is consistent with the practical limits of floating-point display (IEEE 754 double has ~15-17 significant digits).

Files changed: ext/formatting.go, ext/formatting_v2.go

parsePrecision() and parsePrecisionV2() accept unbounded precision
values. An expression like "%.9999999f".format([3.14]) allocates
792MB at cost 501. Add maxPrecision=1000 cap.
@TristonianJones
Copy link
Copy Markdown
Collaborator

/gcbrun

Copy link
Copy Markdown
Collaborator

@TristonianJones TristonianJones left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Would you mind adding test cases which trigger the failure condition?

Comment thread ext/formatting.go Outdated
@Flo354
Copy link
Copy Markdown
Contributor Author

Flo354 commented Mar 24, 2026

I Made maxPrecision configurable with a new StringsMaxPrecision() option.

As requested, default is 100 when version >= 5, no limit for earlier versions to keep backward compatibility.
The limit is passed through the whole parsing chain down to parsePrecision().

As requested, I also added test cases.

@Flo354 Flo354 requested a review from TristonianJones March 24, 2026 09:54
@jnthntatum
Copy link
Copy Markdown
Collaborator

/gcbrun

Comment thread ext/strings.go
@Flo354
Copy link
Copy Markdown
Contributor Author

Flo354 commented Mar 31, 2026

Hello @TristonianJones, I moved the actual set of maxPrecision closer to its usage instead of letting it at the beginning of CompileOptions. And I added a comment.
Tests are running, please, test also on your end to avoid any regression.

@TristonianJones
Copy link
Copy Markdown
Collaborator

/gcbrun

@TristonianJones TristonianJones merged commit 6b8f6d6 into google:master Apr 6, 2026
3 checks passed
Maks1mS pushed a commit to stplr-dev/stplr that referenced this pull request Apr 9, 2026
This PR contains the following updates:

| Package | Type | Update | Change | OpenSSF |
|---|---|---|---|---|
| [github.com/google/cel-go](https://github.com/google/cel-go) | require | minor | `v0.27.0` → `v0.28.0` | [![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/google/cel-go/badge)](https://securityscorecards.dev/viewer/?uri=github.com/google/cel-go) |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/23) for more information.

---

### Release Notes

<details>
<summary>google/cel-go (github.com/google/cel-go)</summary>

### [`v0.28.0`](https://github.com/google/cel-go/releases/tag/v0.28.0)

[Compare Source](google/cel-go@v0.27.0...v0.28.0)

#### High-Level Changes

- **Enhanced JSON Interoperability:** New support for JSON names across the checker, AST, and runtime allows for more seamless data handling when working with JSON-native structures.
- **Improved Developer Tooling:** Integration is now smoother thanks to new utilities for converting Go errors into `cel.Issues` and more descriptive, context-aware error messages.
- **Greater Environment Flexibility:** You can now redeclare variables as constants and export parse limit options, providing finer control over how CEL environments are configured and constrained.
- **Native Struct Improvements:** Support for mixing CEL and native values within native structs simplifies the handling of complex, hybrid data types.

***

#### 🚀 Features

- Add helper method to check whether a function has a singleton binding in [#&#8203;1266](google/cel-go#1266)
- Helper utility for converting a Go error into `cel.Issues` in [#&#8203;1267](google/cel-go#1267)
- Policy API improvements in [#&#8203;1268](google/cel-go#1268)
- CEL Test usability requirements in [#&#8203;1269](google/cel-go#1269)
- Better context-related error messages in [#&#8203;1271](google/cel-go#1271)
- Sort `env.Config` values where reasonable in [#&#8203;1273](google/cel-go#1273)
- Support redeclaring variables as constants in `NewEnv` in [#&#8203;1275](google/cel-go#1275)
- Add support for exporting parse limit options in [#&#8203;1277](google/cel-go#1277)
- Support mixing CEL values and native values in native structs in [#&#8203;1270](google/cel-go#1270)
- Add checker, AST, and type-provider support for JSON names in [#&#8203;1283](google/cel-go#1283)
- JSON field names runtime support in [#&#8203;1286](google/cel-go#1286)
- Optionally include reachable fieldpaths in prompt in [#&#8203;1285](google/cel-go#1285)
- REPL -- cel-spec pb2 and json name support [#&#8203;1294](google/cel-go#1294)

#### 🐞 Bug Fixes

- Fix support for config-based type references in [#&#8203;1265](google/cel-go#1265)
- Check arg kinds in `optional.or` and `.orValue` impl in [#&#8203;1276](google/cel-go#1276)
- Bazel fixes for import in [#&#8203;1278](google/cel-go#1278)
- Support zero-value literals in presence test inlining [#&#8203;1280](google/cel-go#1280)
- Cache concatList.Size() to prevent O(N^2) evaluation time [#&#8203;1291](google/cel-go#1291)
- Preserve runtime error node IDs from Resolve  [#&#8203;1290](google/cel-go#1290)
- Default enable identifier escaping with backticks [#&#8203;1295](google/cel-go#1295)
- Cap format string precision to prevent memory exhaustion [#&#8203;1292](google/cel-go#1292)

#### 🛠️ Maintenance & Internal

- **chore:** Migrate gsutil usage to gcloud storage in [#&#8203;1274](google/cel-go#1274)
- Lint fixes for exported function/type comments in [#&#8203;1279](google/cel-go#1279)
- Lint fixes for import in [#&#8203;1287](google/cel-go#1287)

***

**Full Changelog**: [https://github.com/google/cel-go/compare/v0.27.0...v0.28.0-alpha](https://github.com/google/cel-go/compare/v0.27.0...v0.28.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At 12:00 AM through 04:59 AM and 10:00 PM through 11:59 PM, Monday through Friday (`* 0-4,22-23 * * 1-5`)
  - Only on Sunday and Saturday (`* * * * 0,6`)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDQuNSIsInVwZGF0ZWRJblZlciI6IjQzLjEwNC41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJLaW5kL0RlcGVuZGVuY2llcyJdfQ==-->

Reviewed-on: https://altlinux.space/stapler/stplr/pulls/402
Co-authored-by: Renovate Bot <stapler-helper-bot@noreply.altlinux.space>
Co-committed-by: Renovate Bot <stapler-helper-bot@noreply.altlinux.space>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants