{"id":"GHSA-jwvj-g8pc-cx45","summary":"OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision","details":"### Description\n\nIn OpenFGA, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement.\n\n### Am I affected?\n\nYou are affected if you meet the following preconditions:\n1. You execute **BatchCheck** operations which rely on context. \n2. Multiple checks are sent within a single BatchCheck operation for the same user/object/relation combination, each containing context.\n3. The contexts between those checks differ in a specific way\n\n### Fix\nUpgrade to OpenFGA v1.14.0\n\n### Acknowledgement\nOpenFGA would like to thank @bugbunny-research for the discovery and detailed report.","aliases":["CVE-2026-34972","GO-2026-5483"],"modified":"2026-07-17T21:15:08.854324562Z","published":"2026-04-07T18:05:16Z","database_specific":{"github_reviewed_at":"2026-04-07T18:05:16Z","nvd_published_at":"2026-04-06T21:16:19Z","cwe_ids":["CWE-863"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/openfga/openfga/security/advisories/GHSA-jwvj-g8pc-cx45"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34972"},{"type":"PACKAGE","url":"https://github.com/openfga/openfga"}],"affected":[{"package":{"name":"github.com/openfga/openfga","ecosystem":"Go","purl":"pkg:golang/github.com/openfga/openfga"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.8.0"},{"fixed":"1.14.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.13.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jwvj-g8pc-cx45/GHSA-jwvj-g8pc-cx45.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}