Authzed
Authzed Spicedb: vulnerabilidades y CVE
Authzed Spicedb tiene 15 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55866 | Baja (3.7) | 0.34% | — | 14 sept 2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of… |
| CVE-2026-46668 | Baja (2.3) | 0.35% | — | 10 jun 2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper… |
| CVE-2026-40091 | Media (4.4) | 0.18% | — | 15 abr 2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log level info, the startup "configuration" log… |
| CVE-2025-65111 | Baja (2.9) | 0.22% | — | 21 nov 2025 | SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of… |
| CVE-2025-64529 | Baja (2.7) | 0.25% | — | 10 nov 2025 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator somewhere in their authorization schema;… |
| CVE-2025-49011 | Media (5.3) | 0.32% | — | 6 jun 2025 | SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a… |
| CVE-2024-48909 | Baja (2.4) | 0.32% | — | 14 oct 2024 | SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats… |
| CVE-2024-46989 | Media (5.3) | 0.29% | — | 18 sept 2024 | spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can… |
| CVE-2024-38361 | Media (5.3) | 0.40% | — | 20 jun 2024 | Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources may resolve to… |
| CVE-2024-32001 | Media (4.3) | 0.58% | — | 10 abr 2024 | SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form: `relation folder: folder | folder#parent` with an arrow such as `folder->view` can cause… |
| CVE-2024-27101 | Crítica (9.1) | 0.46% | — | 1 mar 2024 | SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic. Any… |
| CVE-2023-46255 | Media (6.5) | 0.40% | — | 31 oct 2023 | SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having… |
| CVE-2023-35930 | Media (5.3) | 0.45% | — | 26 jun 2023 | SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization decision based on the results of a… |
| CVE-2023-29193 | Alta (7.5) | 0.76% | — | 14 abr 2023 | SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a flag named `--grpc-preshared-key` which is… |
| CVE-2022-21646 | Alta (8.1) | 1.3% | — | 11 ene 2022 | SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation… |