VulnSea

openfga has 8 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The busiest recent month was June 2026 with 3. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. Most affected products: github.com/openfga/openfga (7), openfga (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.3
Publish → KEV
Last 90 days
1 prev 4

Products

  • github.com/openfga/openfga 7
  • openfga 1
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

openfga vulnerabilities

CVEs affecting openfga, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-61709Medium· 5.3
6d ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

Sunlitopenfga · openfgaEPSS 0.34%via NVD
CVE-2026-55689Medium· 6.8
3mo ago

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

Sunlitopenfga · github.com/openfga/openfgaEPSS 0.41%via GHSA
CVE-2026-55170Low
3mo ago

OpenFGA Improper Policy Enforcement

OpenFGA Improper Policy Enforcement

Sunlitopenfga · github.com/openfga/openfgaEPSS 0.34%via GHSA
CVE-2026-48096Medium· 5.0
3mo ago

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

Sunlitopenfga · github.com/openfga/openfgaEPSS 0.10%via OSV
CVE-2026-41131Medium· 5.0
5mo ago

OpenFGA has Improper Policy Enforcement

OpenFGA has Improper Policy Enforcement

Sunlitopenfga · github.com/openfga/openfgaEPSS 0.14%via OSV
CVE-2025-64751Medium
10mo ago

OpenFGA Improper Policy Enforcement

OpenFGA Improper Policy Enforcement

Sunlitopenfga · github.com/openfga/openfgaEPSS 0.29%via OSV
CVE-2024-56323Medium
1y ago

OpenFGA Authorization Bypass

OpenFGA Authorization Bypass

Sunlitopenfga · github.com/openfga/openfgaEPSS 0.45%via OSV
CVE-2023-43645Medium· 5.9
2y ago

OpenFGA Vulnerable to DoS from circular relationship definitions

OpenFGA Vulnerable to DoS from circular relationship definitions

Sunlitopenfga · github.com/openfga/openfgaEPSS 0.75%via OSV
openfga vulnerabilities (CVEs) · VulnSea