OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa
{
"url": "https://pkg.go.dev/vuln/GO-2025-3660",
"review_status": "REVIEWED"
}{
"imports": [
{
"path": "github.com/open-policy-agent/opa/v1/server",
"symbols": [
"Server.makeRego",
"Server.unversionedGetHealthWithPolicy",
"Server.v0QueryPath",
"baseHTTPListener.ListenAndServe",
"baseHTTPListener.ListenAndServeTLS",
"stringPathToDataRef",
"stringPathToRef"
]
}
]
}