{"id":"CVE-2026-34972","aliases":["GHSA-jwvj-g8pc-cx45","GO-2026-5483"],"url":"https://o3.security/vulnerability/CVE-2026-34972","summary":"OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision","details":"### Description\n\nIn OpenFGA, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement.\n\n### Am I affected?\n\nYou are affected if you meet the following preconditions:\n1. You execute **BatchCheck** operations which rely on context. \n2. Multiple checks are sent within a single BatchCheck operation for the same user/object/relation combination, each containing context.\n3. The contexts between those checks differ in a specific way\n\n### Fix\nUpgrade to OpenFGA v1.14.0\n\n### Acknowledgement\nOpenFGA would like to thank @bugbunny-research for the discovery and detailed report.","published":"2026-04-06T20:41:33.414Z","modified":"2026-08-12T03:51:42.983063502Z","cvss":{"score":5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"},"epss":{"score":0.00211,"percentile":0.11501,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openfga/openfga","fixedVersion":"1.14.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34972.json"},{"type":"ADVISORY","url":"https://github.com/openfga/openfga/security/advisories/GHSA-jwvj-g8pc-cx45"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34972"},{"type":"PACKAGE","url":"https://github.com/openfga/openfga"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.983063502Z"}}