Overview OpenFGA v1.8.10 or previous (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.
Am I Affected? If you are using OpenFGA v1.8.10 or previous, specifically under the following conditions, you are affected by this authorization bypass vulnerability: - Calling Check API or ListObjects with an authorization model that has tuple cycle. - Check query cache is enabled, and - There are multiple check / list objects requests involving the tuple cycle within the check query TTL
Fix Upgrade to v1.8.11. This upgrade is backwards compatible.
{ "nvd_published_at": "2025-04-30T19:15:55Z", "cwe_ids": [ "CWE-284", "CWE-863" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-04-30T16:43:33Z" }