PT-2025-24316 · Spicedb · Spicedb

Miparnisari

·

Published

2025-06-06

·

Updated

2025-07-03

·

CVE-2025-49011

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SpiceDB versions prior to 1.44.2
Description The issue affects SpiceDB, an open source database for storing and querying fine-grained authorization data. On schemas involving arrows with caveats on the arrow'ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests may return a negative response when a positive response is expected.
Recommendations For versions prior to 1.44.2, update to version 1.44.2 to resolve the issue. As a temporary workaround, do not use caveats in the schema over an arrow'ed relation.

Exploit

Fix

Improperly Implemented Security Check for Standard

Weakness Enumeration

Related Identifiers

CVE-2025-49011
GHSA-CWWM-HR97-QFXM
GO-2025-3744
OPENSUSE-SU-2025:15225-1

Affected Products

Spicedb