SCA: security update for github.com/openfga/openfga (GHSA-h6c8-cww8-35hf)

medium Tenable Self-Hosted Container Security Plugin ID 439266

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- OpenFGA is a high-performance and flexible authorization/permission engine built for developers and
inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditions, models using
conditions with caching enabled can result in two different check requests producing the same cache key.
This can result in OpenFGA reusing an earlier cached result for a different request. Users are affected if
the model has relations which rely on condition evaluation andncaching is enabled. OpenFGA v1.13.1
contains a patch. (CVE-2026-33729)

Solution

Update the github.com/openfga/openfga library and its related packages to version 1.13.1 or later.

See Also

https://github.com/advisories/GHSA-h6c8-cww8-35hf

Plugin Details

Severity: Medium

ID: 439266

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 3/26/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.95

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-33729

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.8

Threat Score: 1.5

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/26/2026

Vulnerability Publication Date: 3/26/2026

Reference Information

CVE: CVE-2026-33729