CVE-2025-55213
EUVD-2025-2515118.08.2025, 20:15
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <= docker <= v.1.9.4) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed. This vulnerability is fixed in 1.9.5.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openfga | helm_charts | 0.2.40 ≤ 𝑥 < 0.2.42 |
| openfga | openfga | 1.9.3 ≤ 𝑥 < 1.9.5 |
𝑥
= Vulnerable software versions