CVE-2025-64751: OpenFGA Improper Policy Enforcement
Overview OpenFGA v1.4.0 to v1.11.0 (openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed.
Am I Affected? You are affected by this vulnerability if you meet the following preconditions: - You are using OpenFGA v1.4.0 to v1.11.0 - The model has a a relation directly assignable by a type bound pubic access with condition - The same relation is not assignable by a type bound public access without condition - You have a type assigned for the same relation that is a type bound public access without condition
Fix Upgrade to v1.11.1. This upgrade is backwards compatible.
Workaround None
Other sources
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed. This issue has been patched in version 1.11.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64751?
CVE-2025-64751 is considered a high severity vulnerability due to its potential impact on policy enforcement.
How do I fix CVE-2025-64751?
To fix CVE-2025-64751, upgrade OpenFGA to version 1.11.1 or later.
What versions are affected by CVE-2025-64751?
CVE-2025-64751 affects OpenFGA versions from 1.4.0 to 1.11.0.
What specific functionalities are impacted by CVE-2025-64751?
CVE-2025-64751 impacts the execution of certain Check and ListObject calls.
Who is affected by CVE-2025-64751?
Organizations using OpenFGA versions between 1.4.0 and 1.11.0 are affected by CVE-2025-64751.