PT-2025-47815 · Spicedb · Spicedb

CVE-2025-65111

·

Published

2025-11-21

·

Updated

2026-07-30

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SpiceDB versions prior to 1.47.1
Description SpiceDB is a database system used for managing security-critical application permissions. Versions of SpiceDB prior to 1.47.1 may exhibit incomplete LookupResources results when checking permissions under specific schema configurations. This occurs when a schema defines a permission using a union (+) operator, and that union references the same relation on both sides, but with one side pointing to a different permission. Other APIs correctly calculate permissionship.
Recommendations Update to version 1.47.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65111
GHSA-9M7R-G8HG-X3VR
GO-2025-4151
OPENSUSE-SU-2026:21483-1
SUSE-SU-2025:4395-1

Affected Products

Spicedb