CVE-2025-64751

Severity CVSS v4.0:
MEDIUM
Type:
CWE-285 Improper Authorization
Publication date:
21/11/2025
Last modified:
31/12/2025

Description

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:*:*:* 0.1.34 (including) 0.2.49 (excluding)
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:* 1.4.0 (including) 1.11.1 (excluding)