cbcvebase.

Authzed Spicedb vulnerabilities

14 known vulnerabilities affecting authzed/spicedb.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM9LOW2

Vulnerabilities

Page 1 of 1
CVE-2024-27101P3CRITICALCVSS 9.1fixed in 1.29.22024-03-01
CVE-2024-27101 [CRITICAL] CWE-190 CVE-2024-27101: SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-crit SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic. Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject ty
nvd
CVE-2022-21646P3HIGHCVSS 8.1v1.3.0v= 1.3.02022-01-11
CVE-2022-21646 [HIGH] CWE-20 CVE-2022-21646: SpiceDB is a database system for managing security-critical application permissions. Any user making SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation will see `Lookup`/`LookupResources` return a resource as "accessible" if it is *not* accessible by virtue of the inclusion of the wildcard
nvd
CVE-2023-29193P3HIGHCVSS 7.5fixed in 1.19.12023-04-14
CVE-2023-29193 [HIGH] CWE-209 CVE-2023-29193: SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing secur SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a flag named `--grpc-preshared-key` which is used to protect the gRPC API from being accessed by unauthorized requests. The values of this flag are to be considered sensitive, se
nvd
CVE-2025-64529P3MEDIUMCVSS 6.5fixed in 1.45.22025-11-10
CVE-2025-64529 [MEDIUM] CWE-770 CVE-2025-64529: SpiceDB is an open source database system for creating and managing security-critical application pe SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator somewhere in their authorization schema; have configured their SpiceDB server such that `--write-relationships-max-updates-per-call` is bigger than 6500; and issue calls to W
nvd
CVE-2023-46255P4MEDIUMCVSS 6.5fixed in 1.27.0fixed in 1.27.0-rc12023-10-31
CVE-2023-46255 [MEDIUM] CWE-532 CVE-2023-46255: SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-crit SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`) the full URI (including the provided password) is printed, so that the password is shown in the logs
nvd
CVE-2023-35930P4MEDIUMCVSS 5.3v1.22.0v= 1.22.02023-06-26
CVE-2023-35930 [MEDIUM] CWE-913 CVE-2023-35930: SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing secur SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization decision based on the results of a `LookupResources` request with 1.22.0 is affected. For example, using `LookupResources` to find a list of resources to allow access to be
nvd
CVE-2024-38361P4MEDIUMCVSS 5.3fixed in 1.33.12024-06-20
CVE-2024-38361 [MEDIUM] CWE-281 CVE-2024-38361: Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained auth Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources may resolve to `NO_PERMISSION` when permission is expected. If the resource exists under *multiple* folders and the user has access to view more than a
nvd
CVE-2025-49011P4MEDIUMCVSS 5.3fixed in 1.44.22025-06-06
CVE-2025-49011 [MEDIUM] CWE-358 CVE-2025-49011: SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior t SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests may return a negative response when a positive resp
nvd
CVE-2025-65111P4MEDIUMCVSS 5.3fixed in 1.47.12025-11-21
CVE-2025-65111 [MEDIUM] CWE-277 CVE-2025-65111: SpiceDB is an open source database system for creating and managing security-critical application pe SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one side arrows to a different permission). Then SpiceDB
nvd
CVE-2024-46989P4MEDIUMCVSS 5.3fixed in 1.35.32024-09-18
CVE-2024-46989 [MEDIUM] CWE-269 CVE-2024-46989: spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained auth spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can result in no permission being returned when permission is expected. If the resource has multiple groups, and each group is caveated, it
nvd
CVE-2024-32001P4MEDIUMCVSS 4.3fixed in 1.30.12024-04-10
CVE-2024-32001 [MEDIUM] CWE-755 CVE-2024-32001: SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a r SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form: `relation folder: folder | folder#parent` with an arrow such as `folder->view` can cause LookupSubjects to only return the subjects found under subjects for either `folder` or `folder#parent`. This bug only manifests if the same s
nvd
CVE-2026-40091P4MEDIUMCVSS 4.4≥ 1.49.0, < 1.51.1v>= 1.49.0, < 1.51.12026-04-15
CVE-2026-40091 [MEDIUM] CWE-532 CVE-2026-40091: SpiceDB is an open source database system for creating and managing security-critical application pe SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log level info, the startup "configuration" log will include the full datastore DSN, including the plaintext password, inside DatastoreConfig.URI. This issue has been fixed in vers
nvd
CVE-2026-46668P4LOWCVSS 2.3v>= 1.15.0, < 1.52.02026-06-10
CVE-2026-46668 [LOW] CWE-285 CVE-2026-46668: SpiceDB is an open source database system for creating and managing security-critical application pe SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0.
nvd
CVE-2024-48909P4LOWCVSS 2.4≥ 1.35.0, < 1.37.1v>= 1.35.0, < 1.37.12024-10-14
CVE-2024-48909 [LOW] CWE-172 CVE-2024-48909: SpiceDB is an open source database for scalably storing and querying fine-grained authorization data SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for their requests can return a permissionship of `CONDITIONAL` with context marked as missing, even then the c
nvd
Authzed Spicedb vulnerabilities | cvebase