GO-2026-6094None▾ SunlitJSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
github.com/google/cel-go >= 0.22.0, < 0.30.0Upgrade to a patched release:
github.com/google/cel-go 0.30.0Connected by shared product, vendor, weakness, or advisory.
GHSA-gcjh-h69q-9w9gMediumcel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
CVE-2026-19202Critical· 9.1A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences
CVE-2026-93387Medium· 4.3Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page
CVE-2026-93386Medium· 5.4UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page
CVE-2026-93385Medium· 6.5Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page
CVE-2026-93384Low· 3.7Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic