vciy

CVEs we hold for Openfga

Records whose assigning authority named Openfga as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-61709OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-inclusion) when a `but not`…openfga
CVE-2026-55689OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unsetopenfga
CVE-2026-55170OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisionsopenfga
CVE-2026-48096OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store…openfga
CVE-2026-41131OpenFGA has Improper Policy Enforcementopenfga
CVE-2026-40293OpenFGA Playground Preshared Key Exposureopenfga
CVE-2026-34972OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key…openfga
CVE-2026-33729OpenFGA has an Authorization Bypass through cached keysopenfga
CVE-2026-24851OpenFGA Improper Policy Enforcementopenfga
CVE-2025-64751OpenFGA Improper Policy Enforcementopenfga
CVE-2025-55213OpenFGA Authorization Bypass (Check)openfga
CVE-2025-48371OpenFGA Authorization Bypassopenfga
CVE-2025-46331OpenFGA Authorization Bypassopenfga
CVE-2025-25196OpenFGA Authorization Bypassopenfga
CVE-2024-56323OpenFGA Authorization Bypassopenfga
CVE-2024-42473OpenFGA Authorization Bypassopenfga
CVE-2024-31452OpenFGA Authorization Bypassopenfga
CVE-2024-23820OpenFGA DoSopenfga
CVE-2023-45810OpenFGA denial of serviceopenfga
CVE-2023-43645Denial of service from circular relationship definitions in OpenFGAopenfga
CVE-2023-40579OpenFGA Authorization Bypassopenfga
CVE-2023-35933OpenFGA denial of service die to circular relationshipopenfga
CVE-2022-39352OpenFGA Authorization Bypassopenfga
CVE-2022-39342OpenFGA Authorization Bypassopenfga
CVE-2022-39341OpenFGA Authorization Bypassopenfga
CVE-2022-39340OpenFGA Information Disclosureopenfga
CVE-2022-23542OpenFGA Authorization Bypassopenfga

27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.