CVE-2026-34972

MEDIUM5.0EPSS 0.02%

OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision

Published: 4/7/2026Modified: 4/8/2026

Description

### Description In OpenFGA, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. ### Am I affected? You are affected if you meet the following preconditions: 1. You execute **BatchCheck** operations which rely on context. 2. Multiple checks are sent within a single BatchCheck operation for the same user/object/relation combination, each containing context. 3. The contexts between those checks differ in a specific way ### Fix Upgrade to OpenFGA v1.14.0 ### Acknowledgement OpenFGA would like to thank @bugbunny-research for the discovery and detailed report.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.0CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

References (3)