Skip to main content

Vendor/product archive

authzed / spicedb CVEs

Beta · best-effort

13 CVEs tagged to authzed / spicedb0 Critical, 3 High, 2 Medium, 8 Low, 0 Unrated.

CVE-2026-40091

Published Apr 15, 2026

SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log leve…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-65111

Published Nov 21, 2025

SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characte…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64529

Published Nov 10, 2025

SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator so…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-49011

Published Jun 6, 2025

SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed rela…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-48909

Published Oct 14, 2024

SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have ena…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-46989

Published Sep 18, 2024

spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect su…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-38361

Published Jun 20, 2024

Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that ha…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-32001

Published Apr 10, 2024

SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form: `relation folder: folder | folder#parent` with an arrow su…

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-27101

Published Mar 1, 2024

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispat…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46255

Published Oct 31, 2023

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided da…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35930

Published Jun 26, 2023

SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-29193

Published Apr 14, 2023

SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a fl…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21646

Published Jan 11, 2022

SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` o…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1