GHSA-cf98-j28v-49v6
Dashboard / Vulnerabilities / GHSA-cf98-j28v-49v6
Summary: OpenFGA Improper Policy Enforcement
Details: ## Description In OpenFGA, when MySQL is being used as the datastore, two distinct check requests can return the same response. ## Preconditions This applies if the following preconditions are met: 1. You run OpenFGA with MySQL as the datastore 2. Your authorization decisions rely on case-sensitive user strings. ## Fix Upgrade to OpenFGA 1.18.0 or greater. ## Acknowledgements OpenFGA would like to thank @sahajamoth for the detailed report.
References: https://github.com/openfga/openfga/security/advisories/GHSA-cf98-j28v-49v6, https://nvd.nist.gov/vuln/detail/CVE-2026-55170, https://github.com/openfga/helm-charts/commit/96d5517a2693ff5def451dee7d6b9d1baeb281f8, https://github.com/openfga/openfga/commit/a2e0dbefc3e01a95c785f81a3563bc6571b08b11, https://github.com/openfga/helm-charts/releases/tag/openfga-0.3.9, https://github.com/openfga/openfga, https://github.com/openfga/openfga/releases/tag/v1.18.0
Affected packages
Package
Name: github.com/openfga/openfga
Purl: pkg:golang/github.com/openfga/openfga
Affected ranges
Type: SEMVER
Events:
