Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48096

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.

A flaw was found in OpenFGA, an authorization/permission engine. When iterator caching is enabled, distinct authorization check requests can generate identical cache keys. This can cause OpenFGA to reuse an outdated or incorrect cached result for subsequent requests. Such a flaw may lead to unauthorized information disclosure, data integrity issues, or denial of service with low impact.

Меры по смягчению последствий

To mitigate this issue, disable iterator caching in OpenFGA configurations. This prevents the generation of identical cache keys for distinct authorization requests, thereby eliminating the risk of reusing outdated or incorrect cached results. Consult OpenFGA documentation for specific configuration parameters related to iterator caching. Disabling this feature may impact performance depending on the workload, and a service restart may be required for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Fix deferred
Red Hat Ceph Storage 7rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 8rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 9rhceph/grafana-rhel10Fix deferred
Red Hat Enterprise Linux 10grafanaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2487602OpenFGA: OpenFGA: Incorrect authorization due to cache key collision in iterator caching

EPSS

Процентиль: 1%
0.00101
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
nvd
около 2 месяцев назад

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.

CVSS3: 5
github
около 2 месяцев назад

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

EPSS

Процентиль: 1%
0.00101
Низкий

5 Medium

CVSS3