Vulnerabilidades em openfga

27 resultados
Análise Vexday

OpenFGA apresenta 26 vulnerabilidades catalogadas, com 4 divulgadas nos últimos 90 dias, porém nenhuma sob exploração ativa conhecida ou classificada como crítica. A fraqueza predominante (CWE-285) aponta para deficiências em controle de acesso, sugerindo risco moderado em cenários onde autorização é sensível, ainda que sem evidência de ataques em curso.

CVE-2023-35933MEDIUMOpenFGA denial of service die to circular relationshipEPSS 1.1%CVE-2022-39341MEDIUMOpenFGA Authorization BypassEPSS 0.9%CVE-2022-39342MEDIUMOpenFGA Authorization BypassEPSS 0.9%CVE-2022-23542HIGHOpenFGA Authorization BypassEPSS 0.9%CVE-2023-43645MEDIUMDenial of service from circular relationship definitions in OpenFGAEPSS 0.8%CVE-2024-23820MEDIUMOpenFGA DoSEPSS 0.7%CVE-2022-39340MEDIUMOpenFGA Information DisclosureEPSS 0.7%CVE-2024-31452HIGHOpenFGA Authorization BypassEPSS 0.7%CVE-2023-40579MEDIUMOpenFGA Authorization BypassEPSS 0.5%CVE-2024-42473HIGHOpenFGA Authorization BypassEPSS 0.5%CVE-2023-45810MEDIUMOpenFGA denial of serviceEPSS 0.5%CVE-2026-40293MEDIUMOpenFGA Playground Preshared Key ExposureEPSS 0.5%CVE-2025-48371MEDIUMOpenFGA Authorization BypassEPSS 0.5%CVE-2022-39352MEDIUMOpenFGA Authorization BypassEPSS 0.4%CVE-2024-56323MEDIUMOpenFGA Authorization BypassEPSS 0.4%CVE-2025-25196MEDIUMOpenFGA Authorization BypassEPSS 0.4%CVE-2026-55689MEDIUMOpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unsetEPSS 0.4%CVE-2025-46331MEDIUMOpenFGA Authorization BypassEPSS 0.4%CVE-2026-61709MEDIUMOpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-inclusion) when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that userEPSS 0.4%CVE-2026-55170LOWOpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisionsEPSS 0.3%