OpenFGA Authorization Bypass
Package
Affected versions
>= 1.3.6, < 1.8.11
Patched versions
1.8.11
Description
Published to the GitHub Advisory Database
Apr 30, 2025
Reviewed
Apr 30, 2025
Published by the National Vulnerability Database
Apr 30, 2025
Last updated
May 1, 2025
Overview
OpenFGA v1.8.10 or previous (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.
Am I Affected?
If you are using OpenFGA v1.8.10 or previous, specifically under the following conditions, you are affected by this authorization bypass vulnerability:
Fix
Upgrade to v1.8.11. This upgrade is backwards compatible.
References