Vulnerability GHSA-g3pg-frfm-pr2m
Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
11 days ago
September 16, 2026 at 10:15 PM UTC
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
v0.0.1 - v1.18.0
v0.0.1 - v1.18.0
Summary
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
Details
Description
In OpenFGA, the ListUsers API could incorrectly return a user who should have been excluded.
Preconditions
This applies if all of the following are present:
- The authorization model contains a relation defined as an intersection (and) where at least one operand is an exclusion of the form base but not excluded: e.g.
rel1: (public_user but not blocked) and rel2 - The base side of that exclusion is granted through a type-bound public wildcard (e.g. user:*).
- A user excluded by the but not clause is also granted, via a concrete tuple, through another operand of the intersection.
- Your application uses ListUsers to enumerate or enforce access
Fix
Upgrade to OpenFGA v1.18.1 or greater.
Acknowledgements
OpenFGA would like to thank @5ud0er for the detailed report.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 hours ago
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user in github.com/openfga/openfga
v0.0.1 - v1.18.0 GO-2026-6488
v0.0.1 - v1.18.0 GO-2026-6488
Unknown
3 months ago
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset in github.com/openfga/openfga
v0.0.1 - v1.17.1 GO-2026-5423
v0.0.1 - v1.17.1 GO-2026-5423
Unknown
3 months ago
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision in github.com/openfga/openfga
v1.8.0 - v1.13.1 GO-2026-5483
v1.8.0 - v1.13.1 GO-2026-5483
Unknown
3 months ago
OpenFGA Improper Policy Enforcement in github.com/openfga/openfga
v0.0.1 - v1.17.1 GO-2026-5322
v0.0.1 - v1.17.1 GO-2026-5322
Unknown
3 months ago
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning in github.com/openfga/openfga
v0.0.1 - v1.15.1 GO-2026-5239
v0.0.1 - v1.15.1 GO-2026-5239
Impacted packages
Timeline
Published
11 days ago
September 16, 2026 at 10:15 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:11 PM UTC