PT-2025-46219 · Spicedb · Spicedb
Published
2025-11-10
·
Updated
2025-11-21
·
CVE-2025-64529
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SpiceDB versions prior to 1.45.2
Description
SpiceDB is a database system for managing application permissions. Versions prior to 1.45.2 are susceptible to an issue where a successful response is incorrectly returned from a
WriteRelationships call when the call actually fails due to payload size limitations imposed by the datastore. This can lead to incorrect permission check results if relationships are read to resolve the relation involving the exclusion operator. The issue occurs when the --write-relationships-max-updates-per-call configuration is set above 6500 and a large number of updates are sent in a WriteRelationships call.Recommendations
Update to version 1.45.2 or later.
As a workaround, set the
--write-relationships-max-updates-per-call configuration to 1000.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spicedb