A AegiFlow
LOWCVSS 2.1EPSS 0.2%

CVE-2026-55170

OpenFGA Improper Policy Enforcement

Published
2026-06-18
Modified
2026-07-21
EPSS percentile
16%
Aliases
GHSA-cf98-j28v-49v6
Sources
github-advisory

Summary

## Description In OpenFGA, when MySQL is being used as the datastore, two distinct check requests can return the same response. ## Preconditions This applies if the following preconditions are met: 1. You run OpenFGA with MySQL as the datastore 2. Your authorization decisions rely on case-sensitive user strings. ## Fix Upgrade to OpenFGA 1.18.0 or greater. ## Acknowledgements OpenFGA would like to thank @sahajamoth for the detailed report.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/openfga/openfga1.18.0

Remediation: Upgrade to 1.18.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.