CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead o...Show more |
1Openpolicyagent 1Open Policy Agent Jun 17, 2026 Sep 8, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, which allows users to provide a set of built-in functions that should be...Show more |
1Openpolicyagent 1Open Policy Agent Jun 17, 2026 Jun 30, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. |
1Openpolicyagent 1Open Policy Agent Jun 17, 2026 May 19, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. |
1Openpolicyagent 1Open Policy Agent Jun 17, 2026 Feb 9, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 OPA is an open source, general-purpose policy engine. Under certain conditions, pretty-printing an abstract syntax tree (AST) that contains synthetic nodes could change the logic of some statements by reordering array li...Show more |