RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Mar 2026Clear ×Project: OpenFGAClear ×
OpenFGAv1.13.1SecurityMar 24, 2026

A maintenance release fixes a disclosed security vulnerability in Check requests with conditions and caching enabled, which could return incorrect cached results. The fix addresses the interaction between conditional checks and caching.

Check if affected (1)

  • securitymediumCVE-2026-33729 and GHSA-h6c8-cww8-35hf fixed

    Applies if Check requests use conditions and caching is enabled.

    The fix addresses CVE-2026-33729 and GHSA-h6c8-cww8-35hf in Check requests with conditions and caching enabled, which could return incorrect cached results. This correction ships in this release.

Source
OpenFGAv1.13.0SecurityMar 23, 2026

This release adds experimental AuthZen 1.0 support and changes observability output for list-objects operations. It also includes fixes for recoverable panics.

Source
OpenFGAv1.12.1SecurityMar 19, 2026

OpenFGA v1.12.1 contains a dependency version update and a correction to OTLP endpoint handling. The available release information points to changes that affect operator configuration and dependency versions, while internal implementation refactors do not affect users directly.

Source
OpenFGAv1.12.0SecurityMar 13, 2026

A maintenance release adds gRPC message-size configuration, changes TLS certificate rotation handling, and updates an experimental default. It also tightens tuple validation, fixes correctness issues, and updates the Go toolchain for disclosed advisories.

Action needed (2)

  • securityhighGo toolchain version 1.25.8

    The Go toolchain is updated to version 1.25.8 to address standard library vulnerabilities identified by GO-2026-4603 and GO-2026-4601.

  • breakingStricter tuple string validation

    Tuple validation now fails when a tuple string contains Unicode control characters or null bytes.

Check if affected (1)

  • breakingThe pipeline_list_objects experimental default

    Applies if you set pipeline_list_objects, set listObjects-pipeline-enabled, or use a custom featureflag client.

    pipeline_list_objects is enabled by default in experimental settings. The ListObjects pipeline can be disabled by setting listObjects-pipeline-enabled to false.

Source
Browse by month