github.com/open-policy-agent/opa
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
Activity
- Latest release
- 1w ago
- Total releases
- 71
- Cadence
- ~17 days
- Last 12 months
- 25
Reach
- Stars
- 12.2k
Details
- First release
- Nov 07, 2016
| Version | Released | |
|---|---|---|
v1.20.2
patch
|
v1.20.2
patch
Dependencies (55)
+ 47 more |
|
v1.20.1
patch
|
v1.20.1
patch
Dependencies (55)
+ 47 more |
|
v1.20.0
minor
|
v1.20.0
minor
Dependencies (55)
+ 47 more |
|
v1.19.1
patch
|
v1.19.1
patch
Dependencies (55)
+ 47 more |
|
v1.19.0
minor
|
v1.19.0
minor
Dependencies (55)
+ 47 more |
|
v1.18.2
patch
|
v1.18.2
patch
Dependencies (56)
+ 48 more |
|
v1.18.1
patch
|
v1.18.1
patch
Dependencies (56)
+ 48 more |
|
v1.18.0
minor
|
v1.18.0
minor
Dependencies (56)
+ 48 more |
|
v1.17.1
patch
|
v1.17.1
patch
Dependencies (54)
+ 46 more |
|
v1.17.0
minor
|
v1.17.0
minor
Dependencies (54)
+ 46 more |
|
v1.16.2
patch
|
v1.16.2
patch
Dependencies (57)
+ 49 more |
|
v1.16.1
patch
|
v1.16.1
patch
Dependencies (57)
+ 49 more |
|
v1.16.0
minor
|
v1.16.0
minor
Dependencies (57)
+ 49 more |
|
v1.15.2
patch
|
v1.15.2
patch
Dependencies (52)
+ 44 more |
|
v1.15.1
patch
|
v1.15.1
patch
Dependencies (52)
+ 44 more |
|
v1.15.0
minor
|
v1.15.0
minor
Dependencies (52)
+ 44 more |
|
v1.14.1
patch
|
v1.14.1
patch
Dependencies (51)
+ 43 more |
|
v1.14.0
minor
|
v1.14.0
minor
Dependencies (51)
+ 43 more |
|
v1.13.2
patch
|
v1.13.2
patch
Dependencies (51)
+ 43 more |
|
v1.13.1
patch
|
v1.13.1
patch
Dependencies (51)
+ 43 more |
|
v1.13.0
minor
|
v1.13.0
minor
Dependencies (51)
+ 43 more |
|
v1.12.3
patch
|
v1.12.3
patch
Dependencies (51)
+ 43 more |
|
v1.12.2
patch
|
v1.12.2
patch
Dependencies (51)
+ 43 more |
|
v1.12.1
minor
|
v1.12.1
minor
Dependencies (51)
+ 43 more |
|
v1.11.1
minor
|
v1.11.1
minor
Dependencies (51)
+ 43 more |
|
v1.1.0
minor
1 CVE
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (46)
+ 38 more |
|
v1.0.1
major
1 CVE
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.1
major
Dependencies (46)
+ 38 more |
|
v0.67.1
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.67.1
minor
Dependencies (45)
+ 37 more |
|
v0.63.0
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.63.0
minor
Dependencies (44)
+ 36 more |
|
v0.61.0
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.61.0
minor
Dependencies (43)
+ 35 more |
|
v0.59.0
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.59.0
minor
Dependencies (42)
+ 34 more |
|
v0.58.0
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.58.0
minor
Dependencies (42)
+ 34 more |
|
v0.54.0
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.54.0
minor
Dependencies (41)
+ 33 more |
|
v0.53.1
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.53.1
minor
Dependencies (40)
+ 32 more |
|
v0.51.0
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.51.0
minor
Dependencies (40)
+ 32 more |
|
v0.50.2
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.50.2
minor
Dependencies (41)
+ 33 more |
|
v0.49.1
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.49.1
minor
Dependencies (40)
+ 32 more |
|
v0.47.4
patch
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.47.4
patch
Dependencies (41)
+ 33 more |
|
v0.47.2
patch
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.47.2
patch
Dependencies (41)
+ 33 more |
|
v0.47.1
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.47.1
minor
Dependencies (41)
+ 33 more |
|
v0.46.1
patch
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.46.1
patch
Dependencies (41)
+ 33 more |
|
v0.46.0
minor
2 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.46.0
minor
Dependencies (41)
+ 33 more |
|
v0.39.0
minor
4 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-33082
GO-2022-0574
GHSA-2m4x-4q9j-w97g
Jul 01, 2022
Denial of service in github.com/open-policy-agent/opa An issue in the AST parser of Open Policy Agent makes it possible for attackers to cause a Denial of Service attack from a crafted input. Fixed in
0.42.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-28946
GHSA-x7f3-62pm-9p38
GO-2022-0587
May 20, 2022
Out of bounds memory access in github.com/open-policy-agent/opa
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. Fixed in
0.40.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.39.0
minor
Dependencies (34)
+ 26 more |
|
v0.38.0
minor
4 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-33082
GO-2022-0574
GHSA-2m4x-4q9j-w97g
Jul 01, 2022
Denial of service in github.com/open-policy-agent/opa An issue in the AST parser of Open Policy Agent makes it possible for attackers to cause a Denial of Service attack from a crafted input. Fixed in
0.42.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-28946
GHSA-x7f3-62pm-9p38
GO-2022-0587
May 20, 2022
Out of bounds memory access in github.com/open-policy-agent/opa
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. Fixed in
0.40.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.38.0
minor
Dependencies (34)
+ 26 more |
|
v0.37.1
minor
5 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23628
GO-2022-0316
GHSA-hcw3-j74m-qc58
Jul 27, 2022
Incorrect calculation in github.com/open-policy-agent/opa Pretty-printing an AST that contains synthetic nodes can change the logic of some statements by reordering array literals. Fixed in
0.37.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-33082
GO-2022-0574
GHSA-2m4x-4q9j-w97g
Jul 01, 2022
Denial of service in github.com/open-policy-agent/opa An issue in the AST parser of Open Policy Agent makes it possible for attackers to cause a Denial of Service attack from a crafted input. Fixed in
0.42.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-28946
GHSA-x7f3-62pm-9p38
GO-2022-0587
May 20, 2022
Out of bounds memory access in github.com/open-policy-agent/opa
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. Fixed in
0.40.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.37.1
minor
Dependencies (33)
+ 25 more |
|
v0.35.0
minor
5 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23628
GO-2022-0316
GHSA-hcw3-j74m-qc58
Jul 27, 2022
Incorrect calculation in github.com/open-policy-agent/opa Pretty-printing an AST that contains synthetic nodes can change the logic of some statements by reordering array literals. Fixed in
0.37.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-33082
GO-2022-0574
GHSA-2m4x-4q9j-w97g
Jul 01, 2022
Denial of service in github.com/open-policy-agent/opa An issue in the AST parser of Open Policy Agent makes it possible for attackers to cause a Denial of Service attack from a crafted input. Fixed in
0.42.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-28946
GHSA-x7f3-62pm-9p38
GO-2022-0587
May 20, 2022
Out of bounds memory access in github.com/open-policy-agent/opa
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. Fixed in
0.40.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.35.0
minor
Dependencies (24)
+ 16 more |
|
v0.35.0-rc1
pre
5 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23628
GO-2022-0316
GHSA-hcw3-j74m-qc58
Jul 27, 2022
Incorrect calculation in github.com/open-policy-agent/opa Pretty-printing an AST that contains synthetic nodes can change the logic of some statements by reordering array literals. Fixed in
0.37.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-33082
GO-2022-0574
GHSA-2m4x-4q9j-w97g
Jul 01, 2022
Denial of service in github.com/open-policy-agent/opa An issue in the AST parser of Open Policy Agent makes it possible for attackers to cause a Denial of Service attack from a crafted input. Fixed in
0.42.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-28946
GHSA-x7f3-62pm-9p38
GO-2022-0587
May 20, 2022
Out of bounds memory access in github.com/open-policy-agent/opa
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. Fixed in
0.40.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.35.0-rc1
pre
Dependencies (23)
+ 15 more |
|
v0.34.1
minor
5 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23628
GO-2022-0316
GHSA-hcw3-j74m-qc58
Jul 27, 2022
Incorrect calculation in github.com/open-policy-agent/opa Pretty-printing an AST that contains synthetic nodes can change the logic of some statements by reordering array literals. Fixed in
0.37.2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-33082
GO-2022-0574
GHSA-2m4x-4q9j-w97g
Jul 01, 2022
Denial of service in github.com/open-policy-agent/opa An issue in the AST parser of Open Policy Agent makes it possible for attackers to cause a Denial of Service attack from a crafted input. Fixed in
0.42.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-28946
GHSA-x7f3-62pm-9p38
GO-2022-0587
May 20, 2022
Out of bounds memory access in github.com/open-policy-agent/opa
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. Fixed in
0.40.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.34.1
minor
Dependencies (23)
+ 15 more |
|
v0.30.2
patch
4 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-33082
GO-2022-0574
GHSA-2m4x-4q9j-w97g
Jul 01, 2022
Denial of service in github.com/open-policy-agent/opa An issue in the AST parser of Open Policy Agent makes it possible for attackers to cause a Denial of Service attack from a crafted input. Fixed in
0.42.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-28946
GHSA-x7f3-62pm-9p38
GO-2022-0587
May 20, 2022
Out of bounds memory access in github.com/open-policy-agent/opa
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. Fixed in
0.40.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.30.2
patch
Dependencies (22)
+ 14 more |
|
v0.30.1
patch
4 CVEs
CVE-2025-46569
GO-2025-3660
GHSA-6m8w-jc87-6cr7
May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa Fixed in
1.4.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-8260
GO-2024-3141
GHSA-c77r-fh37-x2px
Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability in github.com/open-policy-agent/opa OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. Fixed in
0.68.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-33082
GO-2022-0574
GHSA-2m4x-4q9j-w97g
Jul 01, 2022
Denial of service in github.com/open-policy-agent/opa An issue in the AST parser of Open Policy Agent makes it possible for attackers to cause a Denial of Service attack from a crafted input. Fixed in
0.42.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-28946
GHSA-x7f3-62pm-9p38
GO-2022-0587
May 20, 2022
Out of bounds memory access in github.com/open-policy-agent/opa
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. Fixed in
0.40.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.30.1
patch
Dependencies (22)
+ 14 more |