PT-2026-34222 · Openfga · Openfga

CVE-2026-41131

·

Published

2026-04-21

·

Updated

2026-07-30

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenFGA versions prior to 1.14.1
Description In specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This may lead to the reuse of an earlier cached result for a subsequent request. This occurs when the model has relations relying on condition evaluation and caching is enabled.
Recommendations Upgrade to version 1.14.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41131
GHSA-57J5-QWP2-VQP6
GO-2026-5136
OPENSUSE-SU-2026:21483-1

Affected Products

Openfga