Impact
SpiceDB is an open source database for managing application permissions. From versions 1.34.0 to 1.53.x, the system can return a permanently granted permission (PERMISSIONSHIP_HAS_PERMISSION) instead of the intended conditional or denied state because the functions checkRequestToKey() and checkRequestToKeyWithCanonical() omit CheckHints when forming dispatch cache keys. Under the conditions of intersecting or excluding relations, a subject that traverses both caveated and non‑caveated branches, and when LookupResources with a context parameter runs concurrently with CheckPermission or CheckBulkPermissions for the same resource and subject, a cache entry computed for one hint set can be reused for a semantically different check. This allows a user to obtain permission without satisfying the required caveat. The issue is fixed in version 1.54.0.
Affected Systems
authzed's SpiceDB versions 1.34.0 through 1.53.x are affected. Any deployment that uses the internal dispatch cache, performs permission checks that involve intersecting or excluding relations, a subject reachable through both caveated and non‑caveated branches, and concurrently runs LookupResources with a context parameter during CheckPermission or CheckBulkPermissions for the same resource and subject, will be vulnerable. The fix was introduced in release 1.54.0; upgrading to that version or later eliminates the issue.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and EPSS score is < 1%, indicating a low likelihood of exploitation. Exploitation requires a specific combination of concurrent permission checks, an enabled dispatch result cache, and a permission graph that contains both caveated and non‑caveated branches. While an attacker with knowledge of the permission structure could trigger the cache poisoning, widespread attacks would likely be constrained by these requirements.
OpenCVE Enrichment
Github GHSA