Openfga
Openfga: vulnerabilidades y CVE
Openfga tiene 27 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses10
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-61709 | Media (5.3) | 0.35% | — | 16 sept 2026 | OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection… |
| CVE-2026-55689 | Alta (8.1) | 0.41% | — | 9 jul 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and… |
| CVE-2026-55170 | Baja (2.1) | 0.34% | — | 9 jul 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and… |
| CVE-2026-48096 | Media (5.3) | 0.13% | — | 10 jun 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an… |
| CVE-2026-41131 | Media (5) | 0.23% | — | 22 abr 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the… |
| CVE-2026-40293 | Media (6.5) | 0.50% | — | 17 abr 2026 | OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server… |
| CVE-2026-34972 | Alta (8.8) | 0.27% | — | 6 abr 2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks… |
| CVE-2026-33729 | Media (5.8) | 0.31% | — | 27 mar 2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditions, models using conditions with… |
| CVE-2026-24851 | Media (5.8) | 0.33% | — | 6 feb 2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2.51, v.1.8.5 <=… |
| CVE-2025-64751 | Media (5.8) | 0.29% | — | 21 nov 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <=… |
| CVE-2025-55213 | Media (5.8) | 0.32% | — | 18 ago 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <=… |
| CVE-2025-48371 | Media (5.8) | 0.48% | — | 22 may 2025 | OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization… |
| CVE-2025-46331 | Media (5.8) | 0.39% | — | 30 abr 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are… |
| CVE-2025-25196 | Media (5.8) | 0.43% | — | 19 feb 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to… |
| CVE-2024-56323 | Media (5.8) | 0.45% | — | 13 ene 2025 | OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions:… |
| CVE-2024-42473 | Crítica (9.8) | 0.53% | — | 12 ago 2024 | OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should… |
| CVE-2024-31452 | Crítica (9.8) | 0.66% | — | 16 abr 2024 | OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs. You are very likely… |
| CVE-2024-23820 | Media (6.5) | 0.73% | — | 26 ene 2024 | OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model and tuples used, a call to `ListObjects` may not release… |
| CVE-2023-45810 | Alta (7.5) | 0.51% | — | 17 oct 2023 | OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerable to a denial of service attack. When a number of `ListObjects` calls… |
| CVE-2023-43645 | Media (5.9) | 0.94% | — | 27 sept 2023 | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerable to a denial of service attack when certain Check calls are executed against authorization models… |
| CVE-2023-40579 | Media (6.5) | 0.55% | — | 25 ago 2023 | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API.… |
| CVE-2023-35933 | Alta (7.5) | 1.1% | — | 26 jun 2023 | OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vulnerable to a DoS attack when Check and ListObjects calls are executed against authorization models… |
| CVE-2022-23542 | Crítica (9.8) | 0.95% | — | 20 dic 2022 | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization… |
| CVE-2022-39352 | Crítica (9.8) | 0.45% | — | 8 nov 2022 | OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization bypass under certain conditions. You are affected by this vulnerability… |
| CVE-2022-39342 | Crítica (9.8) | 0.95% | — | 25 oct 2022 | OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users whose model has a relation defined as a tupleset (the right hand side… |
| CVE-2022-39341 | Crítica (9.8) | 0.95% | — | 25 oct 2022 | OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users who have wildcard (`*`) defined on tupleset relations in their… |
| CVE-2022-39340 | Media (5.3) | 0.76% | — | 25 oct 2022 | OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.