CVE-2026-34972

MEDIUM5.0EPSS 0.02%

OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision

發布日:2026/4/7修改日:2026/4/8

描述

### Description In OpenFGA, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. ### Am I affected? You are affected if you meet the following preconditions: 1. You execute **BatchCheck** operations which rely on context. 2. Multiple checks are sent within a single BatchCheck operation for the same user/object/relation combination, each containing context. 3. The contexts between those checks differ in a specific way ### Fix Upgrade to OpenFGA v1.14.0 ### Acknowledgement OpenFGA would like to thank @bugbunny-research for the discovery and detailed report.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.0CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

參考連結(3)