OpenFGA is vulnerable to a DoS attack. When a number of ListObjects calls are executed, in some scenarios, those calls are not releasing resources even after a response has been sent, and the service as a whole becomes unresponsive.
Upgrade to v1.3.4. This upgrade is backwards compatible.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-400"
],
"nvd_published_at": "2023-10-17T23:15:12Z",
"github_reviewed_at": "2023-10-18T18:25:58Z"
}