CVE-2026-41131

Published Apr 22, 2026

Last updated 2 months ago

Overview

Description
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result for a subsequent request. The preconditions for vulnerability are the model having relations which rely on condition evaluation and the user having caching enabled. OpenFGA v1.14.1 contains a fix.
Source
security-advisories@github.com
NVD status
Analyzed
Products
helm_charts, openfga

Risk scores

CVSS 3.1

Type
Secondary
Base score
5
Impact score
3.4
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Severity
MEDIUM

Weaknesses

security-advisories@github.com
CWE-706

Social media

Hype score
Not currently trending

Configurations