Improper resource allocation In github.com/openfga/openfga
Description
OpenFGA denial of service
Overview
OpenFGA is vulnerable to a DoS attack. In some scenarios that depend on the model and tuples used, a call to ListObjects may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an "out of memory" error and terminate.
Fix
Upgrade to v1.4.3. This upgrade is backwards compatible.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | 1.4.3 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.