OPenFGA
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 28 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 25, 2022 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-inclusion) when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisions
OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoning
OpenFGA has Improper Policy Enforcement
OpenFGA Playground Preshared Key Exposure
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
OpenFGA has an Authorization Bypass through cached keys
OpenFGA Improper Policy Enforcement
Monitor OPenFGA in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.