openfga has 8 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The busiest recent month was June 2026 with 3. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. Most affected products: github.com/openfga/openfga (7), openfga (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 4
Products
- github.com/openfga/openfga 7
- openfga 1
Worst active — by depth score
CVE-2026-55689Medium· 6.8OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset37CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions33CVE-2026-61709Medium· 5.3OpenFGA is an authorization and permission engine built for developers29CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…28CVE-2026-41131Medium· 5.0OpenFGA has Improper Policy Enforcement28
openfga vulnerabilities
CVEs affecting openfga, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-61709Medium· 5.3OpenFGA is an authorization and permission engine built for developers
OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…
CVE-2026-55689Medium· 6.8OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
CVE-2026-55170LowOpenFGA Improper Policy Enforcement
OpenFGA Improper Policy Enforcement
CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
CVE-2026-41131Medium· 5.0OpenFGA has Improper Policy Enforcement
OpenFGA has Improper Policy Enforcement
CVE-2025-64751MediumOpenFGA Improper Policy Enforcement
OpenFGA Improper Policy Enforcement
CVE-2024-56323MediumOpenFGA Authorization Bypass
OpenFGA Authorization Bypass
CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions
OpenFGA Vulnerable to DoS from circular relationship definitions