OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning in github.com/openfga/openfga
{
"review_status": "UNREVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-5239"
}