Vulnerability GHSA-g3pg-frfm-pr2m

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
11 days ago
September 16, 2026 at 10:15 PM UTC
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
v0.0.1 - v1.18.0
v0.0.1 - v1.18.0

Summary

OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user

Details

Description

In OpenFGA, the ListUsers API could incorrectly return a user who should have been excluded.

Preconditions

This applies if all of the following are present:

  • The authorization model contains a relation defined as an intersection (and) where at least one operand is an exclusion of the form base but not excluded: e.g. rel1: (public_user but not blocked) and rel2
  • The base side of that exclusion is granted through a type-bound public wildcard (e.g. user:*).
  • A user excluded by the but not clause is also granted, via a concrete tuple, through another operand of the intersection.
  • Your application uses ListUsers to enumerate or enforce access

Fix

Upgrade to OpenFGA v1.18.1 or greater.

Acknowledgements

OpenFGA would like to thank @5ud0er for the detailed report.

Timeline

Published
11 days ago
September 16, 2026 at 10:15 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:11 PM UTC