Openfga

Openfga

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 09.07.2026 21:06:22
  • Zuletzt bearbeitet 14.07.2026 01:28:44

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set...

  • EPSS 0.25%
  • Veröffentlicht 09.07.2026 21:04:28
  • Zuletzt bearbeitet 14.07.2026 01:22:35

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier c...

  • EPSS 0.1%
  • Veröffentlicht 10.06.2026 15:09:59
  • Zuletzt bearbeitet 12.06.2026 00:46:45

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subse...

  • EPSS 0.15%
  • Veröffentlicht 21.04.2026 23:38:29
  • Zuletzt bearbeitet 24.04.2026 13:44:37

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could resul...

  • EPSS 0.29%
  • Veröffentlicht 17.04.2026 20:47:06
  • Zuletzt bearbeitet 24.08.2026 13:18:31

OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key...

  • EPSS 0.21%
  • Veröffentlicht 06.04.2026 20:41:33
  • Zuletzt bearbeitet 24.07.2026 21:10:00

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation...

  • EPSS 0.24%
  • Veröffentlicht 27.03.2026 00:27:40
  • Zuletzt bearbeitet 14.04.2026 01:04:41

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditions, models using conditions with caching enabled can result in two di...

  • EPSS 0.31%
  • Veröffentlicht 06.02.2026 18:15:58
  • Zuletzt bearbeitet 24.02.2026 20:52:16

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2.51, v.1.8.5 <= docker <= v.1.11.2) are vulnerable ...

  • EPSS 0.3%
  • Veröffentlicht 21.11.2025 01:24:32
  • Zuletzt bearbeitet 31.12.2025 13:43:35

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable...

  • EPSS 0.32%
  • Veröffentlicht 18.08.2025 19:23:33
  • Zuletzt bearbeitet 14.01.2026 17:10:47

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <= docker <= v.1.9.4) are vulnerable to...