PT-2025-24316 · Spicedb · Spicedb

·

CVE-2025-49011

·

Published

2025-06-06

·

Updated

2025-07-03

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SpiceDB versions prior to 1.44.2
Description The issue affects SpiceDB, an open source database for storing and querying fine-grained authorization data. On schemas involving arrows with caveats on the arrow'ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests may return a negative response when a positive response is expected.
Recommendations For versions prior to 1.44.2, update to version 1.44.2 to resolve the issue. As a temporary workaround, do not use caveats in the schema over an arrow'ed relation.

Exploit

Fix

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49011
GHSA-CWWM-HR97-QFXM
GO-2025-3744
OPENSUSE-SU-2025:15225-1

Affected Products

Spicedb