CVE-2026-46668 PUBLISHED

SpiceDB: Caveat structures with nested lists can result in improper cache reuse

Assigner: GitHub_M
Reserved: 15.05.2026 Published: 10.06.2026 Updated: 10.06.2026

SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor authzed
Product spicedb
Versions
  • Version >= 1.15.0, < 1.52.0 is affected

References

Problem Types

  • CWE-285: Improper Authorization CWE