RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Mar 2026Clear ×Project: OpenFGAClear ×
OpenFGAv1.13.1SecurityMar 24, 2026

A maintenance release fixes a disclosed security vulnerability in Check requests with conditions and caching enabled, which could return incorrect cached results. The fix addresses the interaction between conditional checks and caching.

Check if affected (1)

  • securitymediumCVE-2026-33729 and GHSA-h6c8-cww8-35hf fixed

    Applies if Check requests use conditions and caching is enabled.

    The fix addresses CVE-2026-33729 and GHSA-h6c8-cww8-35hf in Check requests with conditions and caching enabled, which could return incorrect cached results. This correction ships in this release.

Source
OpenFGAv1.12.0SecurityMar 13, 2026

A maintenance release adds gRPC message-size configuration, changes TLS certificate rotation handling, and updates an experimental default. It also tightens tuple validation, fixes correctness issues, and updates the Go toolchain for disclosed advisories.

Action needed (2)

  • securityhighGo toolchain version 1.25.8

    The Go toolchain is updated to version 1.25.8 to address standard library vulnerabilities identified by GO-2026-4603 and GO-2026-4601.

  • breakingStricter tuple string validation

    Tuple validation now fails when a tuple string contains Unicode control characters or null bytes.

Check if affected (1)

  • breakingThe pipeline_list_objects experimental default

    Applies if you set pipeline_list_objects, set listObjects-pipeline-enabled, or use a custom featureflag client.

    pipeline_list_objects is enabled by default in experimental settings. The ListObjects pipeline can be disabled by setting listObjects-pipeline-enabled to false.

Source
Browse by month