github.com/authzed/spicedb
Open Source, Google Zanzibar-inspired database for scalably storing and querying fine-grained authorization data
Activity
- Latest release
- 2d ago
- Total releases
- 61
- Cadence
- ~18 days
- Last 12 months
- 19
Reach
- Stars
- 7.0k
Details
- First release
- Sep 23, 2021
| Version | Released | |
|---|---|---|
v1.56.2
patch
|
v1.56.2
patch
Dependencies (113)
+ 105 more |
|
v1.56.1
patch
|
v1.56.1
patch
Dependencies (113)
+ 105 more |
|
v1.56.0
minor
|
v1.56.0
minor
Dependencies (112)
+ 104 more |
|
v1.55.0
minor
|
v1.55.0
minor
Dependencies (112)
+ 104 more |
|
v1.54.0
minor
|
v1.54.0
minor
Dependencies (109)
+ 101 more |
|
v1.53.0
minor
1 CVE
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev |
v1.53.0
minor
Dependencies (107)
+ 99 more |
|
v1.52.0
minor
1 CVE
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev |
v1.52.0
minor
Dependencies (107)
+ 99 more |
|
v1.51.1
patch
2 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev |
v1.51.1
patch
Dependencies (112)
+ 104 more |
|
v1.51.0
minor
3 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40091
GO-2026-5465
GHSA-jf4f-rr2c-9m58
Jun 25, 2026
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb Fixed in
1.51.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev |
v1.51.0
minor
Dependencies (112)
+ 104 more |
|
v1.50.0
minor
3 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40091
GO-2026-5465
GHSA-jf4f-rr2c-9m58
Jun 25, 2026
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb Fixed in
1.51.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev |
v1.50.0
minor
Dependencies (112)
+ 104 more |
|
v1.49.2
patch
3 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40091
GO-2026-5465
GHSA-jf4f-rr2c-9m58
Jun 25, 2026
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb Fixed in
1.51.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev |
v1.49.2
patch
Dependencies (111)
+ 103 more |
|
v1.49.1
patch
3 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40091
GO-2026-5465
GHSA-jf4f-rr2c-9m58
Jun 25, 2026
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb Fixed in
1.51.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev |
v1.49.1
patch
Dependencies (109)
+ 101 more |
|
v1.49.0
minor
4 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40091
GO-2026-5465
GHSA-jf4f-rr2c-9m58
Jun 25, 2026
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb Fixed in
1.51.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev |
v1.49.0
minor
Dependencies (109)
+ 101 more |
|
v1.48.0
minor
3 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev |
v1.48.0
minor
Dependencies (106)
+ 98 more |
|
v1.47.1
patch
3 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev |
v1.47.1
patch
Dependencies (105)
+ 97 more |
|
v1.46.2
minor
4 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.46.2
minor
Dependencies (103)
+ 95 more |
|
v1.47.0
minor
4 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.47.0
minor
Dependencies (103)
+ 95 more |
|
v1.46.1
patch
4 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.46.1
patch
Dependencies (103)
+ 95 more |
|
v1.46.0
minor
4 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.46.0
minor
Dependencies (102)
+ 94 more |
|
v1.45.4
patch
4 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.45.4
patch
Dependencies (102)
+ 94 more |
|
v1.45.3
patch
4 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.45.3
patch
Dependencies (101)
+ 93 more |
|
v1.45.2
minor
4 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.45.2
minor
Dependencies (101)
+ 93 more |
|
v1.44.4
patch
5 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.44.4
patch
Dependencies (108)
+ 100 more |
|
v1.44.3
patch
5 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.44.3
patch
Dependencies (108)
+ 100 more |
|
v1.44.0
minor
6 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.44.0
minor
Dependencies (111)
+ 103 more |
|
v1.41.0
minor
6 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.41.0
minor
Dependencies (108)
+ 100 more |
|
v1.40.1
minor
6 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.40.1
minor
Dependencies (108)
+ 100 more |
|
v1.38.0
minor
6 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.38.0
minor
Dependencies (107)
+ 99 more |
|
v1.36.3
minor
7 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-48909
GO-2024-3200
GHSA-3c32-4hq9-6wgj
Oct 15, 2024
SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not in github.com/authzed/spicedb SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not in github.com/authzed/spicedb Fixed in
1.37.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.36.3
minor
Dependencies (105)
+ 97 more |
|
v1.35.3
minor
7 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-55866
GO-2026-5133
GHSA-4vrg-r928-h5vv
Jun 25, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb Fixed in
1.54.0
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-48909
GO-2024-3200
GHSA-3c32-4hq9-6wgj
Oct 15, 2024
SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not in github.com/authzed/spicedb SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not in github.com/authzed/spicedb Fixed in
1.37.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.35.3
minor
Dependencies (104)
+ 96 more |
|
v1.31.0
minor
7 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.31.0
minor
Dependencies (94)
+ 86 more |
|
v1.30.1
minor
7 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.30.1
minor
Dependencies (91)
+ 83 more |
|
v1.29.5
patch
8 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.29.5
patch
Dependencies (90)
+ 82 more |
|
v1.29.0
minor
9 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.29.0
minor
Dependencies (90)
+ 82 more |
|
v1.26.0
minor
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.26.0
minor
Dependencies (82)
+ 74 more |
|
v1.25.0
minor
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.25.0
minor
Dependencies (82)
+ 74 more |
|
v1.25.0-rc4
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.25.0-rc4
pre
Dependencies (82)
+ 74 more |
|
v1.25.0-rc3
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.25.0-rc3
pre
Dependencies (82)
+ 74 more |
|
v1.25.0-rc1
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.25.0-rc1
pre
Dependencies (82)
+ 74 more |
|
v1.24.0-rc3
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.24.0-rc3
pre
Dependencies (83)
+ 75 more |
|
v1.24.0-rc2
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.24.0-rc2
pre
Dependencies (82)
+ 74 more |
|
v1.24.0-rc1
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.24.0-rc1
pre
Dependencies (82)
+ 74 more |
|
v1.23.1
patch
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.23.1
patch
Dependencies (87)
+ 79 more |
|
v1.23.0
minor
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.23.0
minor
Dependencies (87)
+ 79 more |
|
v1.23.0-rc4
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.23.0-rc4
pre
Dependencies (87)
+ 79 more |
|
v1.23.0-rc2
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.23.0-rc2
pre
Dependencies (87)
+ 79 more |
|
v1.22.1
minor
11 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-35930
GO-2023-1871
GHSA-m54h-5x5f-5m6r
Aug 20, 2024
SpiceDB's LookupResources may return partial results in github.com/authzed/spicedb SpiceDB's LookupResources may return partial results in github.com/authzed/spicedb Fixed in
1.22.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.22.1
minor
Dependencies (87)
+ 79 more |
|
v1.22.0-rc7
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.22.0-rc7
pre
Dependencies (87)
+ 79 more |
|
v1.22.0-rc5
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.22.0-rc5
pre
Dependencies (87)
+ 79 more |
|
v1.22.0-rc4
pre
10 CVEs
CVE-2026-46668
GO-2026-5514
GHSA-mqcf-gqvg-rmhm
Jun 25, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb Fixed in
1.52.0
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4465
GHSA-vhvq-fv9f-wh4q
Feb 17, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.49.1
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65111
GO-2025-4151
GHSA-9m7r-g8hg-x3vr
Nov 25, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb Fixed in
1.47.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64529
GO-2025-4120
GHSA-pm3x-jrhh-qcr7
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb Fixed in
1.45.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49011
GO-2025-3744
GHSA-cwwm-hr97-qfxm
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb Fixed in
1.44.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-46989
GO-2024-3131
GHSA-jhg6-6qrx-38mr
Sep 25, 2024
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb Fixed in
1.35.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-46255
GO-2023-2166
GHSA-jg7w-cxjv-98c2
Aug 21, 2024
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb Fixed in
1.27.0-rc1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38361
GO-2024-2939
GHSA-grjv-gjgr-66g2
Jun 28, 2024
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb Fixed in
1.33.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-27101
GO-2024-2597
GHSA-h3m7-rqc4-7h9p
Jun 04, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb Fixed in
1.29.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-32001
GO-2024-2716
GHSA-j85q-46hg-36p2
Jun 04, 2024
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb Fixed in
1.30.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.22.0-rc4
pre
Dependencies (86)
+ 78 more |