CVE-2026-33505 | ory keto up to 26.1.x GetRelationships API sql injection (GHSA-c38g-mx2c-9wf2)
A vulnerability classified as critical was found in ory keto up to 26.1.x. Impacted is an unknown function of the component GetRelationships API. Executing a manipulation can lead to sql injection.
This vulnerability is registered as CVE-2026-33505. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.