๐Ÿ” CVE Alert

CVE-2026-55866

LOW 3.7

SpiceDBChecks involving relations with caveats can result in unconditional permission when conditional permission is expected

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or PERMISSIONSHIP_NO_PERMISSION because checkRequestToKey() and checkRequestToKeyWithCanonical() in internal/dispatch/keys/computed.go omit CheckHints when constructing dispatch Check cache keys. The incorrect result requires a permission combining relations with intersection or exclusion, a subject reachable through caveated and non-caveated branches, LookupResources with a context parameter running concurrently with CheckPermission or CheckBulkPermissions for the same resource and subject, and an enabled dispatch result cache. Under these conditions, a result computed for one hint set can poison the cache entry used by a semantically different authorization check, allowing permission without satisfying the caveat. This issue is fixed in version 1.54.0.

CWE CWE-863
Vendor authzed
Product spicedb
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for authzed spicedb

Be the first to know when new low vulnerabilities affecting authzed spicedb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

authzed / spicedb
>= 1.34.1, < 1.54.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/authzed/spicedb/security/advisories/GHSA-4vrg-r928-h5vv github.com: https://github.com/authzed/spicedb/pull/3188 github.com: https://github.com/authzed/spicedb/commit/44a1c9f266bd8a884bfebfc27181210302541b9b github.com: https://github.com/authzed/spicedb/commit/ccde792fc48750740d025d4286d5c2c88614cd30 github.com: https://github.com/authzed/spicedb/releases/tag/v1.54.0