Improper Policy Enforcement in OpenFGA Authorization Engine by OpenFGA
CVE-2025-55213

5.8MEDIUM

Key Information:

Vendor

Openfga

Status
Vendor
CVE Published:
18 August 2025

What is CVE-2025-55213?

OpenFGA has a vulnerability due to improper policy enforcement that may occur when executing certain Check and ListObject calls. This critical issue affects versions 1.9.3 and 1.9.4 of the OpenFGA authorization engine and its associated Helm charts and Docker instances. Users are encouraged to upgrade to version 1.9.5, where this vulnerability has been addressed. For more information, refer to the security advisory on OpenFGA's GitHub repository.

Affected Version(s)

openfga >= 1.9.3, < 1.9.5

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.