GHSA-g3pg-frfm-pr2m: Medium severity go/github.com/openfga/openfga vulnerability

Published Sep 16, 2026
·
Updated

Description

In OpenFGA, the ListUsers API could incorrectly return a user who should have been excluded.

Preconditions

This applies if all of the following are present:

- The authorization model contains a relation defined as an intersection (and) where at least one operand is an exclusion of the form base but not excluded: e.g. rel1: (publicuser but not blocked) and rel2 - The base side of that exclusion is granted through a type-bound public wildcard (e.g. user:). - A user excluded by the but not clause is also granted, via a concrete tuple, through another operand of the intersection. - Your application uses ListUsers to enumerate or enforce access

Fix

Upgrade to OpenFGA v1.18.1 or greater.

Acknowledgements

OpenFGA would like to thank @5ud0er for the detailed report.

Affected Software

1 affected componentFixes available
go/github.com/openfga/openfga<=1.18.0
1.18.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/openfga/openfga to a version that resolves this vulnerability.

    Fixed in 1.18.1
  2. Upgrade

    Upgrade openfga to a version that resolves this vulnerability.

    Fixed in 1.18.1

Event History

Sep 16, 2026
Advisory Published
via GitHub·10:15 PM
Data Sourced
via GitHub·10:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected in practice?

Affected deployments use ListUsers and have an authorization model with an intersection containing a “base but not excluded” operand. The base must be granted through a type-bound public wildcard, and the excluded user must also have a concrete-tuple grant through another operand of that intersection.

2

What can an attacker or unauthorized user gain from this issue?

A user who should be excluded can be incorrectly returned by ListUsers when the specified model and tuple conditions are met. This can expose that user as authorized if the application relies on ListUsers to enumerate or enforce access.

3

Are default configurations affected?

The issue is conditional rather than universally affecting all OpenFGA configurations. It requires the specific intersection, exclusion, wildcard, and concrete-tuple arrangement described in the advisory, as well as application use of ListUsers.

4

How can I remediate the issue?

Upgrade OpenFGA to version 1.18.1 or later. If upgrading is not immediately possible, avoid using ListUsers to enumerate or enforce access for models that meet the affected relation and tuple conditions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203