VendorsAuthzedspicedbany version
Vulnerabilities

Authzed SpiceDB any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2024-27101
Integer overflow in chunking helper causes dispatching to miss elements or panic
Published 2024-03-01 · Analyzed
9.1EPSS 0.005
CVE-2023-29193
SpiceDB binding metrics port to untrusted networks and can leak command-line flags
Published 2023-04-14 · Modified
8.7EPSS 0.008
CVE-2023-46255
`SPICEDB_DATASTORE_CONN_URI` is leaked when URI cannot be parsed
Published 2023-10-31 · Modified
6.5EPSS 0.004
CVE-2025-64529
SpiceDB's WriteRelationships fails silently if payload is too big
Published 2025-11-10 · Analyzed
6.5EPSS 0.002
CVE-2026-40091
SpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logs
Published 2026-04-14 · Analyzed
6.0EPSS 0.002
CVE-2024-38361
Permissions processing error in spacedb
Published 2024-06-20 · Analyzed
5.3EPSS 0.004
CVE-2025-49011
SpiceDB checks involving relations with caveats can result in no permission when permission is expected
Published 2025-06-06 · Analyzed
5.3EPSS 0.003
CVE-2024-46989
Multiple caveats on resources of the same type can result in no permission when permission is expected
Published 2024-09-18 · Analyzed
5.3EPSS 0.003
CVE-2025-65111
SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
Published 2025-11-21 · Analyzed
5.3EPSS 0.002
CVE-2024-32001
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used
Published 2024-04-10 · Analyzed
4.3EPSS 0.006
CVE-2024-48909
SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not
Published 2024-10-14 · Analyzed
2.4EPSS 0.003