{"id":"CVE-2023-45810","aliases":["GHSA-hr4f-6jh8-f2vq","GO-2023-2121"],"url":"https://o3.security/vulnerability/CVE-2023-45810","summary":"OpenFGA denial of service","details":"OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerable to a denial of service attack. When a number of `ListObjects` calls are executed, in some scenarios, those calls are not releasing resources even after a response has been sent, and given a sufficient call volume the service as a whole becomes unresponsive. This issue has been addressed in version 1.3.4 and the upgrade is considered backwards compatible. There are no known workarounds for this vulnerability.","published":"2023-10-17T22:29:00.293Z","modified":"2026-07-15T01:49:10.150480110Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openfga/openfga","fixedVersion":"1.3.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45810.json"},{"type":"ADVISORY","url":"https://github.com/openfga/openfga/security/advisories/GHSA-hr4f-6jh8-f2vq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45810"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:10.150480110Z"}}