Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

redhat логотип

CVE-2026-34972

4 месяца назад

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. This vulnerability is fixed in 1.14.0.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2026-34972

4 месяца назад

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. This vulnerability is fixed in 1.14.0.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-jwvj-g8pc-cx45

4 месяца назад

OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-34972

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. This vulnerability is fixed in 1.14.0.

CVSS3: 4.2
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-34972

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. This vulnerability is fixed in 1.14.0.

CVSS3: 5
0%
Низкий
4 месяца назад
github логотип
GHSA-jwvj-g8pc-cx45

OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision

CVSS3: 5
0%
Низкий
4 месяца назад

Уязвимостей на страницу