Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12750 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. This issue has been patched in version 1.8.11. |
Github GHSA |
GHSA-w222-m46c-mgh6 | OpenFGA Authorization Bypass |
Wed, 31 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openfga helm Charts
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:*:*:* cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Openfga helm Charts
|
|
| Metrics |
cvssV3_1
|
Thu, 01 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Apr 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. This issue has been patched in version 1.8.11. | |
| Title | OpenFGA Authorization Bypass | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-01T18:52:23.855Z
Reserved: 2025-04-22T22:41:54.911Z
Link: CVE-2025-46331
Updated: 2025-05-01T18:52:19.088Z
Status : Analyzed
Published: 2025-04-30T19:15:55.490
Modified: 2025-12-31T15:06:58.233
Link: CVE-2025-46331
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:59Z
EUVD
Github GHSA