Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48096

Опубликовано: 10 июн. 2026
Источник: nvd
CVSS3: 5
CVSS3: 5.3
EPSS Низкий

Описание

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:openfga:*:*
Версия до 0.3.5 (исключая)
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*
Версия до 1.16.0 (исключая)

EPSS

Процентиль: 1%
0.00101
Низкий

5 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 5
redhat
около 2 месяцев назад

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.

CVSS3: 5
github
около 2 месяцев назад

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

EPSS

Процентиль: 1%
0.00101
Низкий

5 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-345