Open Policy Agent is a compact but strategically deployed policy-as-code engine that sits at enforcement points across cloud-native infrastructure, Kubernetes environments, and API gateways through products such as Open Policy Agent itself and Gatekeeper. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and concentrate in authentication-bypass and input-validation weaknesses that are characteristic of systems evaluating untrusted policy logic and control decisions. Defenders should treat this vendor's advisories as high-priority for any deployment where policy decisions gate access to sensitive resources; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openpolicyagent over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36085CRITICAL Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, which allows users to provide a s | Sep 8, 2022 | 9.8 | 32 | NO | NO |
CVE-2024-8260HIGH A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user | Aug 30, 2024 | 7.3 | 26 | NO | NO |
CVE-2022-33082HIGH An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Jun 30, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-28946HIGH An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via trigger | May 19, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-23628MEDIUM OPA is an open source, general-purpose policy engine. Under certain conditions, pretty-printing an abstract syntax tree (AST) that contains synthetic nodes could change the logic o | Feb 9, 2022 | 5.3 | 20 | NO | NO |
CVE-2021-43979MEDIUM Styra Open Policy Agent (OPA) Gatekeeper through 3.7.0 mishandles concurrency, sometimes resulting in incorrect access control. The data replication mechanism allows policies to ac | Nov 17, 2021 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openpolicyagent.
Media articles that mention a CVE ID that affects a product developed by Openpolicyagent — matched by CVE ID, not by vendor name.