PatchSiren

openfga CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM openfga CVE published 2026-07-09

CVE-2026-55689

CVE-2026-55689 is a MEDIUM severity vulnerability in OpenFGA's OIDC authenticator. Prior to version 1.18.0, the OIDC authenticator skipped JWT audience validation when certain conditions were met, potentially allowing unauthorized access. This issue is fixed in version 1.18.0. Users of OpenFGA prior to version 1.18.0 who utilize OIDC authentication should verify their configurations and update to the late [truncated]

LOW openfga CVE published 2026-07-09

CVE-2026-55170

CVE-2026-55170 is an authorization bypass vulnerability in OpenFGA, a developer-focused authorization/permission engine. When MySQL is used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns may treat case-distinct values as equivalent. This could lead to two distinct check requests returning the same response. [truncated]

MEDIUM openfga CVE published 2026-06-10

CVE-2026-48096

CVE-2026-48096 is a medium-severity vulnerability in OpenFGA, an authorization/permission engine. The issue allows two distinct check requests to produce the same cache key when iterator caching is enabled, leading to OpenFGA reusing an earlier cached result for a subsequent request. This vulnerability has been patched in version 1.16.0.

MEDIUM openfga CVE published 2026-04-17

CVE-2026-40293

OpenFGA, an authorization/permission engine for developers, has a vulnerability in versions 0.1.4 through 1.13.1. When configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is enabled by default but not designed for production environments. Users running [truncated]

MEDIUM openfga CVE published 2026-04-06

CVE-2026-34972

CVE-2026-34972 is a vulnerability in OpenFGA, a high-performance and flexible authorization/permission engine. From version 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. This vulnerability is fixed in version 1.14.0. The vulnerability has a medium severity and is related [truncated]