Dependency scanning
Check whether github.com/authzed/spicedb is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
GO-2026-4465
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic
CVE-2024-38361
SpiceDB exclusions can result in no permission returned when permission expected
CVE-2024-32001
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used
CVE-2024-27101
Integer overflow in chunking helper causes dispatching to miss elements or panic
CVE-2023-35930
SpiceDB's LookupResources may return partial results
CVE-2023-46255
SpiceDB leaks information in log files when URI cannot be parsed
CVE-2023-29193
SpiceDB binding metrics port to untrusted networks and can leak command-line flags
CVE-2026-46668
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
CVE-2026-40091
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs
CVE-2026-46668
SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb
CVE-2026-40091
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb
CVE-2026-55866
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected
CVE-2026-55866
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb
CVE-2025-64529
SpiceDB WriteRelationships fails silently if payload is too big
CVE-2025-65111
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
CVE-2025-65111
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb
CVE-2025-64529
SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb
CVE-2025-49011
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb
CVE-2024-48909
SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not in github.com/authzed/spicedb
CVE-2024-46989
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb
CVE-2023-35930
SpiceDB's LookupResources may return partial results in github.com/authzed/spicedb
CVE-2022-21646
Lookup operations do not take into account wildcards in SpiceDB in github.com/authzed/spicedb
GHSA-vhvq-fv9f-wh4q
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb
CVE-2024-32001
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb
CVE-2024-38361
SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb
CVE-2024-27101
Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb
CVE-2023-46255
SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb
CVE-2023-29193
SpiceDB binding metrics port to untrusted networks and can leak command-line flags in github.com/authzed/spicedb
CVE-2025-49011
SpiceDB checks involving relations with caveats can result in no permission when permission is expected
CVE-2024-46989
SpiceDB having multiple caveats on resources of the same type may improperly result in no permission
CVE-2024-48909
SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not
CVE-2022-21646
Lookup operations do not take into account wildcards in SpiceDB
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes