Authzed / Spicedb
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-55866 | SpiceDBChecks involving relations with caveats can result in unconditional permission when conditional permission is expected | LOW | 3.7 | Sep 14, 2026 |
| CVE-2026-46668 | SpiceDB: Caveat structures with nested lists can result in improper cache reuse | LOW | 2.3 | Jun 10, 2026 |
| CVE-2026-40091 | SpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logs | MEDIUM | 6.0 | Apr 14, 2026 |
| CVE-2025-65111 | SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results | LOW | 2.9 | Nov 21, 2025 |
| CVE-2025-64529 | SpiceDB's WriteRelationships fails silently if payload is too big | LOW | 2.7 | Nov 10, 2025 |
| CVE-2025-49011 | SpiceDB checks involving relations with caveats can result in no permission when permission is expected | MEDIUM | 5.3 | Jun 6, 2025 |
| CVE-2024-48909 | SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not | LOW | 2.4 | Oct 14, 2024 |
| CVE-2024-46989 | Multiple caveats on resources of the same type can result in no permission when permission is expected | MEDIUM | 6.3 | Sep 18, 2024 |
| CVE-2024-38361 | Permissions processing error in spacedb | MEDIUM | 6.3 | Jun 20, 2024 |
| CVE-2024-32001 | SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used | MEDIUM | 4.3 | Apr 10, 2024 |
| CVE-2024-27101 | Integer overflow in chunking helper causes dispatching to miss elements or panic | CRITICAL | 9.1 | Mar 1, 2024 |
| CVE-2023-46255 | `SPICEDB_DATASTORE_CONN_URI` is leaked when URI cannot be parsed | MEDIUM | 6.5 | Oct 31, 2023 |
| CVE-2023-35930 | LookupResources may return partial results in spicedb | MEDIUM | 5.3 | Jun 26, 2023 |
| CVE-2023-29193 | SpiceDB binding metrics port to untrusted networks and can leak command-line flags | HIGH | 8.7 | Apr 14, 2023 |
| CVE-2022-21646 | Lookup operations do not take into account wildcards in SpiceDB | HIGH | 8.1 | Jan 11, 2022 |
Showing 1 to 15 of 15 CVEs