OpenFGA v1.4.0 to v1.11.0 (openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed.
You are affected by this vulnerability if you meet the following preconditions:
Upgrade to v1.11.1. This upgrade is backwards compatible.
None
{
"cwe_ids": [
"CWE-285"
],
"github_reviewed": true,
"github_reviewed_at": "2025-11-20T22:48:55Z",
"nvd_published_at": "2025-11-21T02:15:43Z",
"severity": "MODERATE"
}