CVE-2025-25196·Docker vulnerability
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users on OpenFGA v1.8.4 or previous, specifically under the following conditions are affected by this authorization bypass vulnerability: 1. Calling Check API or ListObjects with a model that has a relation directly assignable to both public access AND userset with the same type. 2. A type bound public access tuple is assigned to an object. 3. userset tuple is not assigned to the same object. and 4. Check request's user field is a userset that has the same type as the type bound public access tuple's user type. Users are advised to upgrade to v1.8.5 which is backwards compatible. There are no known workarounds for this vulnerability.
- Severity
- critical
- Software
- Docker
- Fixed in
- 1.8.5
- Published
- 2025-02-19
Affected versions
Until: 1.8.5
Fixed in: 1.8.5
How to fix this CVE
Update Docker to version 1.8.5 or later to remediate this authorization bypass vulnerability in OpenFGA. The vulnerability allows attackers to bypass permission checks under specific model configurations involving public access and userset relations. Ensure all Docker instances running OpenFGA are patched, as the vulnerability is backwards compatible and requires no additional configuration changes.
sudo dnf update docker-ce docker-ce-cliDefensia detects this vulnerability
How to check if you are affected
- Run 'docker --version' to check the installed Docker version; versions prior to 1.8.5 are vulnerable
- Execute 'docker ps --filter 'label=openfga' to identify running OpenFGA containers and note their image tags
- Check container image digests with 'docker inspect <container_id> | grep -i digest' to verify if patches have been pulled
- Verify the patch by running 'docker pull openfga:v1.8.5' and comparing the digest of the running container against the latest patched image
FAQ
What is CVE-2025-25196?
CVE-2025-25196 is an authorization bypass vulnerability in OpenFGA (bundled with Docker) that allows attackers to bypass permission checks when specific conditions are met: a relation is directly assignable to both public access and userset types, a public access tuple exists, and a userset tuple does not exist on the same object.
Is CVE-2025-25196 being actively exploited?
No, CVE-2025-25196 is not listed in the CISA Known Exploited Vulnerabilities catalog and no public exploits are currently available, though the critical CVSS 9.8 score indicates organizations should prioritize patching.
What versions of Docker are affected by CVE-2025-25196?
All Docker versions shipping OpenFGA prior to v1.8.5 are affected, including Helm charts before openfga-0.2.22. The vulnerability impacts Docker installations with bundled OpenFGA components.
How do I check if my server is vulnerable to CVE-2025-25196?
Run 'docker version' and check if the OpenFGA component version is below 1.8.5; also inspect running containers with 'docker inspect <container_id>' and search for the version label or tag.
Does Defensia detect CVE-2025-25196?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2025-25196 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-25196. Free for 1 server.
Get started free