go

github.com/authzed/spicedb

View on go registry
32 Total advisories
32 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/authzed/spicedb is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

GO-2026-4465

LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic

LOW 3.7
Go

CVE-2024-38361

SpiceDB exclusions can result in no permission returned when permission expected

LOW 2.2
Go

CVE-2024-32001

SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used

HIGH 7.3
Go

CVE-2024-27101

Integer overflow in chunking helper causes dispatching to miss elements or panic

LOW 3.7
Go

CVE-2023-35930

SpiceDB's LookupResources may return partial results

MEDIUM 4.2
Go

CVE-2023-46255

SpiceDB leaks information in log files when URI cannot be parsed

HIGH 8.1
Go

CVE-2023-29193

SpiceDB binding metrics port to untrusted networks and can leak command-line flags

UNKNOWN
Go

CVE-2026-46668

SpiceDB: Caveat structures with nested lists can result in improper cache reuse

MEDIUM 6.0
Go

CVE-2026-40091

SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs

UNKNOWN
Go

CVE-2026-46668

SpiceDB: Caveat structures with nested lists can result in improper cache reuse in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2026-40091

SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs in github.com/authzed/spicedb

LOW 3.7
Go

CVE-2026-55866

SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected

UNKNOWN
Go

CVE-2026-55866

SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb

MEDIUM 6.5
Go

CVE-2025-64529

SpiceDB WriteRelationships fails silently if payload is too big

UNKNOWN
Go

CVE-2025-65111

SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results

UNKNOWN
Go

CVE-2025-65111

SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2025-64529

SpiceDB WriteRelationships fails silently if payload is too big in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2025-49011

SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2024-48909

SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2024-46989

SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2023-35930

SpiceDB's LookupResources may return partial results in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2022-21646

Lookup operations do not take into account wildcards in SpiceDB in github.com/authzed/spicedb

UNKNOWN
Go

GHSA-vhvq-fv9f-wh4q

LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2024-32001

SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2024-38361

SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2024-27101

Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2023-46255

SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb

UNKNOWN
Go

CVE-2023-29193

SpiceDB binding metrics port to untrusted networks and can leak command-line flags in github.com/authzed/spicedb

LOW 3.7
Go

CVE-2025-49011

SpiceDB checks involving relations with caveats can result in no permission when permission is expected

LOW 3.7
Go

CVE-2024-46989

SpiceDB having multiple caveats on resources of the same type may improperly result in no permission

LOW 2.0
Go

CVE-2024-48909

SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not

HIGH 8.1
Go

CVE-2022-21646

Lookup operations do not take into account wildcards in SpiceDB

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes