CVEs we hold for Openfga
Records whose assigning authority named Openfga as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-61709OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-inclusion) when a `but not`…openfga
CVE-2026-55170OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisionsopenfga
CVE-2026-48096OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store…openfga
CVE-2026-34972OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key…openfga
27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.