Openfga

Openfga

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 06.02.2026 18:15:58
  • Zuletzt bearbeitet 24.02.2026 20:52:16

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2.51, v.1.8.5 <= docker <= v.1.11.2) are vulnerable ...

  • EPSS 0.06%
  • Veröffentlicht 21.11.2025 01:24:32
  • Zuletzt bearbeitet 31.12.2025 13:43:35

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable...

  • EPSS 0.07%
  • Veröffentlicht 18.08.2025 19:23:33
  • Zuletzt bearbeitet 14.01.2026 17:10:47

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <= docker <= v.1.9.4) are vulnerable to...

  • EPSS 0.03%
  • Veröffentlicht 22.05.2025 22:20:37
  • Zuletzt bearbeitet 15.01.2026 02:34:33

OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization bypass when certain Check and Lis...

  • EPSS 0.32%
  • Veröffentlicht 30.04.2025 18:27:05
  • Zuletzt bearbeitet 31.12.2025 15:06:58

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when ...

  • EPSS 0.28%
  • Veröffentlicht 19.02.2025 21:15:15
  • Zuletzt bearbeitet 31.12.2025 14:18:13

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Chec...

  • EPSS 0.13%
  • Veröffentlicht 13.01.2025 22:15:14
  • Zuletzt bearbeitet 31.12.2025 14:58:38

OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObj...

  • EPSS 0.07%
  • Veröffentlicht 12.08.2024 13:38:35
  • Zuletzt bearbeitet 01.10.2024 12:21:50

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as ...

  • EPSS 0.12%
  • Veröffentlicht 16.04.2024 22:15:35
  • Zuletzt bearbeitet 05.01.2026 16:20:42

OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs. You are very likely affected if your model involves e...

  • EPSS 0.09%
  • Veröffentlicht 26.01.2024 17:15:13
  • Zuletzt bearbeitet 21.11.2024 08:58:29

OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model and tuples used, a call to `ListObjects` may not release memory properly. So when a suffi...