OpenFGA
v1.20.0SecuritySep 8, 2026
A maintenance release updates the Go toolchain and images to address a security advisory. It also fixes a `ListUsers` deadlock that could cause timeouts with partial results.
Action needed (1)
securitycriticalGo toolchain and images at go1.26.8
The Go toolchain and images are upgraded to use
go1., addressing CVE-2026-39821 and Go advisory26. 8 GO-2026-5026.
All 1 other recorded changesfixes 1
fixes (1)
- - Fixed a deadlock in ListUsers that caused a timeout with partial results when the number of union/intersection operands exceeded
OPENFGA_RESOLVE_NODE_BREADTH_LIMITand the operands each resolved to more than one user. Thank you to [@fabianluque](https://github.com/fabianluque) for the discovery and detailed report! [#3284](https://github.com/openfga/openfga/pull/3284)
Add OpenFGA to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.