VendorsOpenFGAhelm_chartsall versions
Vulnerabilities

OpenFGA Helm Charts

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2024-56323
OpenFGA Authorization Bypass
Published 2025-01-13 · Analyzed
9.8EPSS 0.004
CVE-2025-25196
OpenFGA Authorization Bypass
Published 2025-02-19 · Analyzed
9.8EPSS 0.004
CVE-2025-46331
OpenFGA Authorization Bypass
Published 2025-04-30 · Analyzed
9.8EPSS 0.004
CVE-2025-55213
OpenFGA Authorization Bypass (Check)
Published 2025-08-18 · Analyzed
9.8EPSS 0.003
CVE-2025-48371
OpenFGA Authorization Bypass
Published 2025-05-22 · Analyzed
8.8EPSS 0.005
CVE-2026-24851
OpenFGA Improper Policy Enforcement
Published 2026-02-06 · Analyzed
8.8EPSS 0.003
CVE-2025-64751
OpenFGA Improper Policy Enforcement
Published 2025-11-21 · Analyzed
8.8EPSS 0.003
CVE-2026-34972
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
Published 2026-04-06 · Analyzed
8.8EPSS 0.003
CVE-2026-55689
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
Published 2026-07-09 · Analyzed
8.1EPSS 0.004
CVE-2026-55170
OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisions
Published 2026-07-09 · Analyzed
5.4EPSS 0.003
CVE-2026-48096
OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoning
Published 2026-06-10 · Analyzed
5.3EPSS 0.001
CVE-2026-41131
OpenFGA has Improper Policy Enforcement
Published 2026-04-21 · Analyzed
5.0EPSS 0.002