You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
OpenFGA Improper Policy Enforcement
Low severity
GitHub Reviewed
Published
Jun 17, 2026
in
openfga/openfga
•
Updated Jun 18, 2026
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Learn more on MITRE.
Description
In OpenFGA, when MySQL is being used as the datastore, two distinct check requests can return the same response.
Preconditions
This applies if the following preconditions are met:
Fix
Upgrade to OpenFGA 1.18.0 or greater.
Acknowledgements
OpenFGA would like to thank @sahajamoth for the detailed report.
References