Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2026-55689
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation whe…
Helm Charts
0.3.9 / 1.18.0+
MEDIUM 5.4
CVE-2026-55170
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization deci…
Helm Charts
0.3.9 / 1.18.0+
MEDIUM 5.3
CVE-2026-48096
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check req…
Helm Charts
0.3.5 / 1.16.0+
MEDIUM 5.0
CVE-2026-41131
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with cach…
Helm Charts
0.3.1 / 1.14.1+
MEDIUM 6.5
CVE-2026-40293
OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key…
Openfga
1.14.0+
HIGH 8.8
CVE-2026-34972
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1…
Helm Charts
0.2.62 / 1.14.0+
CRITICAL 9.8
CVE-2026-33729
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to…
Openfga
1.13.1+
HIGH 8.8
CVE-2026-24851
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1…
Helm Charts
0.2.51 / 1.11.3+
HIGH 8.8
CVE-2025-64751
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1…
Helm Charts
0.2.49 / 1.11.1+
CRITICAL 9.8
CVE-2025-55213
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1…
Helm Charts
0.2.42 / 1.9.5+
HIGH 8.8
CVE-2025-48371
OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.…
Helm Charts
0.2.32 / 1.8.13+
CRITICAL 9.8
CVE-2025-46331
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v…
Helm Charts
0.2.29 / 1.8.11+
CRITICAL 9.8
CVE-2025-25196
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (He…
Helm Charts
0.2.22 / 1.8.5+
CRITICAL 9.8
CVE-2024-56323
OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) a…
Helm Charts
0.2.19 / 1.8.3+
CRITICAL 9.8
CVE-2024-42473
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model t…
Openfga
Mitigation only
CRITICAL 9.8
CVE-2024-31452
OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization…
Openfga
1.5.3+
MEDIUM 6.5
CVE-2024-23820
OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on…
Openfga
1.4.3+
HIGH 7.5
CVE-2023-45810
OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerab…
Openfga
1.3.4+
MEDIUM 5.9
CVE-2023-43645
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerable to a denial of service atta…
Openfga
1.3.2+
MEDIUM 6.5
CVE-2023-40579
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are v…
Openfga
1.3.1+
HIGH 7.5
CVE-2023-35933
OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vulnerable to a DoS attack when…
Openfga
1.1.1+
CRITICAL 9.8
CVE-2022-23542
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was di…
Openfga
0.3.1+
CRITICAL 9.8
CVE-2022-39352
OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization by…
Openfga
0.2.5+
CRITICAL 9.8
CVE-2022-39341
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users…
Openfga
0.2.4+
CRITICAL 9.8
CVE-2022-39342
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users…
Openfga
0.2.4+
MEDIUM 5.3
CVE-2022-39340
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization head…
Openfga
0.2.4+