Skip to content

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

Moderate severity GitHub Reviewed Published Jun 5, 2026 in openfga/openfga • Updated Jun 11, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts