CVE-2025-65111Medium· 5.3▾ SunlitSpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and th…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one side arrows to a different permission). Then SpiceDB may have missing LookupResources results when checking the permission. This only affects LookupResources; other APIs calculate permissionship correctly. The issue is fixed in version 1.47.1.
spicedb < 1.47.1Upgrade past the affected range:
spicedb 1.47.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55866Low· 3.7SpiceDB is an open source database system for creating and managing security-critical application permissions
CVE-2025-11554Medium· 6.3A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10
CVE-2025-11395Medium· 5.5A flaw was found in Podman
CVE-2026-20630Medium· 5.5A permissions issue was addressed with additional restrictions
CVE-2026-7891Critical· 9.1Rejected reason: This CVE has been retracted