OpenFGA is vulnerable to a DoS attack. In some scenarios that depend on the model and tuples used, a call to ListObjects may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an "out of memory" error and terminate.
Upgrade to v1.4.3. This upgrade is backwards compatible.
{ "nvd_published_at": "2024-01-26T17:15:13Z", "cwe_ids": [ "CWE-401", "CWE-770" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-26T20:12:00Z" }