OpenFGA is vulnerable to a DoS attack. In some scenarios that depend on the model and tuples used, a call to ListObjects may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an "out of memory" error and terminate.
Upgrade to v1.4.3. This upgrade is backwards compatible.
{
"nvd_published_at": "2024-01-26T17:15:13Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-401",
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2024-01-26T20:12:00Z"
}