CVE-2025-46331

Severity CVSS v4.0:
MEDIUM
Type:
CWE-284 Improper Access Control
Publication date:
30/04/2025
Last modified:
31/12/2025

Description

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:*:*:* 0.1.36 (including) 0.2.29 (excluding)
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:* 1.3.6 (including) 1.8.11 (excluding)