OpenFGA DoS
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
In short
OpenFGA, a permission system, has a bug where repeated calls to ListObjects don't free up memory properly. If an attacker makes many of these calls, the server can run out of memory and crash.
Technical detail
A resource exhaustion vulnerability in OpenFGA's ListObjects function fails to release allocated memory under certain model and tuple configurations, allowing an unauthenticated attacker to trigger denial of service through repeated requests that exhaust server memory and cause termination. The issue is patched in version 1.4.3.
Summary generated and translated by AI from the official description.
OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model and tuples used, a call to `ListObjects` may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an `out of memory` error and terminate. Version 1.4.3 contains a patch for this issue.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
openfga · openfga