Security Advisories for github.com/openfga/openfga in go
Moderate
about 2 months ago
OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response
go
github.com/openfga/openfga
Moderate
about 2 months ago
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
go
github.com/openfga/openfga
Moderate
2 months ago
OpenFGA has an Authorization Bypass through cached keys
go
github.com/openfga/openfga
Moderate
over 2 years ago
OpenFGA Vulnerable to DoS from circular relationship definitions
go
github.com/openfga/openfga
Moderate
almost 3 years ago
OpenFGA vulnerable to denial of service due to circular relationship
go
github.com/openfga/openfga
Moderate
over 3 years ago
OpenFGA Authorization Bypass via tupleset wildcard
go
github.com/openfga/openfga
Moderate
over 3 years ago
OpenFGA subject to Information Disclosure via streamed-list-objects endpoint
go
github.com/openfga/openfga