Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8396-jffm-qx4w

Опубликовано: 11 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

Description

In OpenFGA, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request.

Preconditions

This applies if the following preconditions are present:

  • FGA runs with SharedIteratorCache enabled,
  • FGA runs with ListObjectsIteratorCache enabled.

Fix

Upgrade to version 1.16.0 or greater.

Acknowledgements

OpenFGA would like to thank @j4xT for the discovery and the detailed report.

Пакеты

Наименование

github.com/openfga/openfga

go
Затронутые версииВерсия исправления

< 1.16.0

1.16.0

EPSS

Процентиль: 1%
0.00101
Низкий

5 Medium

CVSS3

Дефекты

CWE-345
CWE-668

Связанные уязвимости

CVSS3: 5
redhat
около 2 месяцев назад

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.

CVSS3: 5
nvd
около 2 месяцев назад

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.

EPSS

Процентиль: 1%
0.00101
Низкий

5 Medium

CVSS3

Дефекты

CWE-345
CWE-668