PT-2025-18710 · Unknown+1 · Open Policy Agent+1

Published

2025-05-01

·

Updated

2025-12-12

·

CVE-2025-46569

CVSS v4.0

7.4

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Open Policy Agent (OPA) versions prior to 1.4.0
Description The issue concerns the Open Policy Agent (OPA), a general-purpose policy engine. In versions prior to 1.4.0, when run as a server, OPA exposes an HTTP Data API. A crafted HTTP request path can inject Rego code into the constructed query used for policy evaluation. Although the evaluation result cannot return other data than what is generated by the requested path, the injected Rego code can be crafted to make the query succeed or fail, potentially leading to oracle attacks or erroneous policy decision results. Additionally, the injected code can be computationally expensive, resulting in a Denial Of Service (DoS) attack.
Recommendations For versions prior to 1.4.0, update to version 1.4.0 to resolve the issue. As a temporary workaround, consider limiting network access to OPA's RESTful APIs to localhost and/or trusted networks, unless necessary for production reasons.

Exploit

Fix

DoS

Incorrect Authorization

OS Command Injection

Code Injection

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

AZL-63067
CVE-2025-46569
ECHO-4D87-77FE-13DC
GHSA-6M8W-JC87-6CR7
GO-2025-3660
OPENSUSE-SU-2025:15059-1
OPENSUSE-SU-2025:15253-1
OPENSUSE-SU-2025:15355-1
OPENSUSE-SU-2025:15370-1
OPENSUSE-SU-2025:15530-1
OPENSUSE-SU-2025:20117-1
OPENSUSE-SU-2025:20160-1
SUSE-SU-2025:02592-1
SUSE-SU-2025_02592-1

Affected Products

Open Policy Agent
Suse