📦 Openfga

by Openfga

🔍 What is Openfga?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-55213

CRITICAL CVSS 9.8 Aug 18, 2025

OpenFGA versions 1.9.3 to 1.9.4 contain an improper policy enforcement vulnerability in Check and ListObject calls. This allows attackers to bypass authorization controls and access resources they sho...

CVE-2025-46331

CRITICAL CVSS 9.8 Apr 30, 2025

OpenFGA versions 1.3.6 through 1.8.10 contain an authorization bypass vulnerability in Check and ListObject calls. This allows attackers to bypass permission checks and access unauthorized resources. ...

CVE-2025-25196

CRITICAL CVSS 9.8 Feb 19, 2025

OpenFGA versions before 1.8.5 contain an authorization bypass vulnerability that allows unauthorized access when specific Check and ListObject API calls are made under certain model configurations. Th...

CVE-2024-56323

CRITICAL CVSS 9.8 Jan 13, 2025

OpenFGA versions 1.3.8 to 1.8.2 contain an authorization bypass vulnerability when using conditions with contextual tuples and caching enabled. Attackers can bypass authorization checks to access unau...

CVE-2026-24851

HIGH CVSS 8.8 Feb 6, 2026

OpenFGA versions 1.8.5 to 1.11.2 have an improper policy enforcement vulnerability that can allow unauthorized access when specific authorization models and tuple configurations exist. The vulnerabili...

CVE-2025-64751

HIGH CVSS 8.8 Nov 21, 2025

OpenFGA versions 1.4.0 to 1.11.0 have an improper policy enforcement vulnerability in Check and ListObject calls. This allows attackers to bypass authorization controls and access resources they shoul...

CVE-2025-48371

HIGH CVSS 8.8 May 22, 2025

OpenFGA versions 1.8.0 through 1.8.12 contain an authorization bypass vulnerability in Check and ListObject API calls. Attackers can bypass intended permissions when specific conditions are met involv...

CVE-2024-42473

HIGH CVSS 7.5 Aug 12, 2024

OpenFGA versions 1.5.7 and 1.5.8 contain an authorization bypass vulnerability when using Check API with models containing 'but not' and 'from' expressions combined with usersets. This allows attacker...

CVE-2024-31452

HIGH CVSS 8.1 Apr 16, 2024

OpenFGA versions 1.5.0 to 1.5.2 contain an authorization bypass vulnerability in Check and ListObjects APIs when using models with exclusion or intersection logic. This allows attackers to bypass inte...