github.com/expr-lang/expr
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/expr-lang/exprpage 1 of 1
- CVE-2025-29786HIGHCVSS 7.5EG 7.5✓ Fixed in 1.17.02025-03-17
Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, it will attempt to compile the entire string and generate an Abstract Syntax Tree (…
- CVE-2025-68156HIGHCVSS 7.5EG 7.5✓ Fixed in 1.17.72025-12-16
Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data struc…
Check whether github.com/expr-lang/expr is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/expr-lang/expr CVEs against the assets you own.
Start Free Scan →