HIGH 8.8 GitHub

CVE-2026-55771

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

### Summary CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. Under certain circumstances, it could lead to incorrect equality comparisons. ### Impact **`EntityIdentifier.equals()` has inverted null/self branches** The `EntityIdentifier.equals()` method has inverted logic for null and self-reference checks, returning true for null comparisons and false for self-comparisons. This does not affect Cedar authorization dec

Affected Products

References

Published: 2026-07-28 · Source: GitHub · Feed updated: 2026-08-04
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-07-28 via GitHub. Affected: maven/com.cedarpolicy:cedar-java < 2.3.6, maven/com.cedarpolicy:cedar-java >= 3.1.2, < 3.4.1, maven/com.cedarpolicy:cedar-java >= 4.0.0, < 4.9.0.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.