CVE-2025-46331

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. This issue has been patched in version 1.8.11.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:*:*:*
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*

History

31 Dec 2025, 15:06

Type Values Removed Values Added
First Time Openfga helm Charts
Openfga
Openfga openfga
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*
cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:*:*:*
References () https://github.com/openfga/openfga/commit/244302e7a8b979d66cc1874a3899cdff7d47862f - () https://github.com/openfga/openfga/commit/244302e7a8b979d66cc1874a3899cdff7d47862f - Patch
References () https://github.com/openfga/openfga/security/advisories/GHSA-w222-m46c-mgh6 - () https://github.com/openfga/openfga/security/advisories/GHSA-w222-m46c-mgh6 - Vendor Advisory

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) OpenFGA es un motor de autorización y permisos flexible y de alto rendimiento, diseñado para desarrolladores e inspirado en Google Zanzibar. Las versiones de OpenFGA v1.8.10 a v1.3.6 (Helm chart &lt;= openfga-0.2.28, docker &lt;= v.1.8.10) son vulnerables a la omisión de la autorización al ejecutar ciertas llamadas a Check y ListObject. Este problema se ha corregido en la versión 1.8.11.

30 Apr 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-30 19:15

Updated : 2025-12-31 15:06


NVD link : CVE-2025-46331

Mitre link : CVE-2025-46331

CVE.ORG link : CVE-2025-46331


JSON object : View

Products Affected

openfga

  • helm_charts
  • openfga
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo