Junglewise Threat Intelligence

CVE-2025-46569: GO-2025-3660 - OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa

CVE-2025-46569 · Severity: medium · CVSS 4 · Published 2025-05-05

Technologies: github.com/open-policy-agent/opa (Go). Vendors: Go.

Executive brief

OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa

Affected products

  • Go github.com/open-policy-agent/opa/v1/server
  • Go github.com/open-policy-agent/opa/server
  • Go github.com/open-policy-agent/opa

Related threats