CVE-2025-55213·Docker vulnerability
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <= docker <= v.1.9.4) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed. This vulnerability is fixed in 1.9.5.
- Severity
- critical
- Software
- Docker
- Fixed in
- 1.9.5
- Published
- 2025-08-18
Affected versions
From: 1.9.3
Until: 1.9.5
Fixed in: 1.9.5
How to fix this CVE
Update Docker to version 1.9.5 or later to patch the authorization bypass vulnerability affecting OpenFGA's policy enforcement logic. This vulnerability allows improper handling of Check and ListObject API calls, potentially granting unauthorized access to protected resources. Apply the update immediately across all production and non-production environments running affected versions.
sudo dnf check-update docker-ce && sudo dnf update docker-ceDefensia detects this vulnerability
How to check if you are affected
- Run 'docker --version' or 'docker version' to identify the currently installed Docker version and compare against the vulnerable range 1.9.3–1.9.4
- Query the OpenFGA authorization service logs for unusual Check or ListObject API calls: grep -i 'check\|listobject' /var/log/docker/*.log or container logs if running in orchestration
- Search authorization audit logs for unexpected policy enforcement outcomes: grep -i 'unauthorized\|access denied\|policy' application logs within the timeframe of potential exploitation
- Verify the patched version is running by executing 'docker version' again and confirming the version string shows 1.9.5 or higher
FAQ
What is CVE-2025-55213?
CVE-2025-55213 is a critical authorization bypass vulnerability in OpenFGA (used by Docker) that incorrectly enforces access policies during Check and ListObject API operations, potentially allowing attackers to bypass permission controls and access restricted resources without proper credentials.
Is CVE-2025-55213 being actively exploited?
No, CVE-2025-55213 is not currently listed in the CISA Known Exploited Vulnerabilities catalog, and no public exploits are available. However, the critical CVSS score of 9.8 warrants immediate patching regardless of active exploitation status.
What versions of Docker are affected by CVE-2025-55213?
Docker versions 1.9.3 through 1.9.4 are vulnerable; the corresponding Helm chart versions openfga-0.2.40 through openfga-0.2.41 are also affected. Version 1.9.5 and later contain the fix.
How do I check if my server is vulnerable to CVE-2025-55213?
Execute 'docker version' or 'docker --version' and check if the version falls between 1.9.3 and 1.9.4 inclusive. If using Kubernetes, run 'helm list -A' and verify OpenFGA Helm chart version is not in the range openfga-0.2.40 to openfga-0.2.41.
Does Defensia detect CVE-2025-55213?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2025-55213 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-55213. Free for 1 server.
Get started free