SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests may return a negative response when a positive response is expected. Version 1.44.2 fixes the issue. As a workaround, do not use caveats in the schema over an arrow’ed relation.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-17360 SpiceDB checks involving relations with caveats can result in no permission when permission is expected
Github GHSA Github GHSA GHSA-cwwm-hr97-qfxm SpiceDB checks involving relations with caveats can result in no permission when permission is expected
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 04 Sep 2025 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:authzed:spicedb:*:*:*:*:*:*:*:*

Fri, 06 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 17:45:00 +0000

Type Values Removed Values Added
Description SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests may return a negative response when a positive response is expected. Version 1.44.2 fixes the issue. As a workaround, do not use caveats in the schema over an arrow’ed relation.
Title SpiceDB checks involving relations with caveats can result in no permission when permission is expected
Weaknesses CWE-358
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-06-06T21:33:23.317Z

Reserved: 2025-05-29T16:34:07.176Z

Link: CVE-2025-49011

cve-icon Vulnrichment

Updated: 2025-06-06T18:38:20.391Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-06T18:15:35.497

Modified: 2025-09-04T16:48:00.090

Link: CVE-2025-49011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-23T09:16:30Z