github.com/openfga/openfga vulnerabilities
CVEs whose affected-version data names the github.com/openfga/openfga package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2026-55689Medium· 6.8OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.41%via GHSA
CVE-2026-55170LowOpenFGA Improper Policy Enforcement
OpenFGA Improper Policy Enforcement
▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.34%via GHSA
CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.10%via OSV
CVE-2026-41131Medium· 5.0OpenFGA has Improper Policy Enforcement
OpenFGA has Improper Policy Enforcement
▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.14%via OSV
CVE-2025-64751MediumOpenFGA Improper Policy Enforcement
OpenFGA Improper Policy Enforcement
▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.29%via OSV
CVE-2024-56323MediumOpenFGA Authorization Bypass
OpenFGA Authorization Bypass
▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.45%via OSV
CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions
OpenFGA Vulnerable to DoS from circular relationship definitions
▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.75%via OSV