OpenFGA v1.4.0 to v1.11.0 (openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed.
You are affected by this vulnerability if you meet the following preconditions: - You are using OpenFGA v1.4.0 to v1.11.0 - The model has a a relation directly assignable by a type bound pubic access with condition - The same relation is not assignable by a type bound public access without condition - You have a type assigned for the same relation that is a type bound public access without condition
Upgrade to v1.11.1. This upgrade is backwards compatible.
None
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-285"
],
"nvd_published_at": "2025-11-21T02:15:43Z",
"github_reviewed_at": "2025-11-20T22:48:55Z",
"github_reviewed": true
}