CVE-2025-46331: OpenFGA Authorization Bypass
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. This issue has been patched in version 1.8.11.
Other sources
Overview OpenFGA v1.8.10 or previous (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.
Am I Affected? If you are using OpenFGA v1.8.10 or previous, specifically under the following conditions, you are affected by this authorization bypass vulnerability: - Calling Check API or ListObjects with an authorization model that has tuple cycle. - Check query cache is enabled, and - There are multiple check / list objects requests involving the tuple cycle within the check query TTL
Fix Upgrade to v1.8.11. This upgrade is backwards compatible.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46331?
CVE-2025-46331 has a high severity due to potential authorization bypass vulnerabilities.
How do I fix CVE-2025-46331?
To fix CVE-2025-46331, upgrade OpenFGA to version 1.8.11 or later.
Which versions are affected by CVE-2025-46331?
CVE-2025-46331 affects OpenFGA versions 1.8.10 and earlier.
What impact does CVE-2025-46331 have on my system?
CVE-2025-46331 can allow unauthorized access through specific Check and ListObject calls.
Is there a specific package for CVE-2025-46331?
Yes, the affected package is github.com/openfga/openfga, specifically versions up to 1.8.10.