Vulnerability Description
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed. This issue has been patched in version 1.11.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openfga | Helm Charts | >= 0.1.34, < 0.2.49 |
| Openfga | Openfga | >= 1.4.0, < 1.11.1 |
Related Weaknesses (CWE)
References
- https://github.com/openfga/openfga/releases/tag/v1.11.1Release Notes
- https://github.com/openfga/openfga/security/advisories/GHSA-2c64-vmv2-hgfcVendor Advisory
FAQ
What is CVE-2025-64751?
CVE-2025-64751 is a vulnerability with a CVSS score of 8.8 (HIGH). OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2...
How severe is CVE-2025-64751?
CVE-2025-64751 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64751?
Check the references section above for vendor advisories and patch information. Affected products include: Openfga Helm Charts, Openfga Openfga.