Vulnerability GO-2026-6488
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 hours ago
September 28, 2026 at 04:43 PM UTC
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user in github.com/openfga/openfga
v0.0.1 - v1.18.0
v0.0.1 - v1.18.0
Summary
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user in github.com/openfga/openfga
Details
OpenFGA: ListUsers returns a deliberately-excluded user when a but not exclusion under a type-bound wildcard is intersected (and) with another relation that also grants that user in github.com/openfga/openfga
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
11 days ago
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
v0.0.1 - v1.18.0 GHSA-g3pg-frfm-pr2m
v0.0.1 - v1.18.0 GHSA-g3pg-frfm-pr2m
Unknown
3 months ago
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset in github.com/openfga/openfga
v0.0.1 - v1.17.1 GO-2026-5423
v0.0.1 - v1.17.1 GO-2026-5423
Unknown
3 months ago
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision in github.com/openfga/openfga
v1.8.0 - v1.13.1 GO-2026-5483
v1.8.0 - v1.13.1 GO-2026-5483
Unknown
3 months ago
OpenFGA Improper Policy Enforcement in github.com/openfga/openfga
v0.0.1 - v1.17.1 GO-2026-5322
v0.0.1 - v1.17.1 GO-2026-5322
Unknown
3 months ago
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning in github.com/openfga/openfga
v0.0.1 - v1.15.1 GO-2026-5239
v0.0.1 - v1.15.1 GO-2026-5239
Impacted packages
Timeline
Published
3 hours ago
September 28, 2026 at 04:43 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:00 PM UTC