PT-2026-48462 · Openfga · Openfga
CVE-2026-48096
·
Published
2026-06-10
·
Updated
2026-07-30
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenFGA versions prior to 1.16.0
Description
When iterator caching is enabled, specifically with
SharedIteratorCache and ListObjectsIteratorCache, two distinct check requests can produce the same cache key. This causes the system to reuse a previously cached result for a subsequent, different request.Recommendations
Upgrade to version 1.16.0 or greater.
As a temporary workaround, consider disabling
SharedIteratorCache and ListObjectsIteratorCache to prevent cache key collisions.Exploit
Fix
Insufficient Verification of Data Authenticity
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openfga