Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46668

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 4.3

Описание

SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0.

A flaw was found in SpiceDB, an open-source database system for managing application permissions. This vulnerability occurs due to improper cache reuse when processing caveat structures that contain nested lists. This could lead to unexpected behavior or a low impact on confidentiality, potentially resulting in minor information disclosure.

Отчет

Red Hat ships SpiceDB as a dependency in the Management Platform service (cloud.redhat.com). The vulnerability involves improper cache reuse when processing caveat structures with nested lists, which could lead to minor information disclosure. The affected version range is 1.15.0 to before 1.52.0.

Меры по смягчению последствий

Avoid using caveat structures with nested lists in SpiceDB permission definitions until the fix (v1.52.0) is applied. Alternatively, update SpiceDB to version 1.52.0 or later.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-237
https://bugzilla.redhat.com/show_bug.cgi?id=2487703github.com/authzed/spicedb: SpiceDB: Improper cache reuse vulnerability in caveat structures

4.3 Medium

CVSS3

Связанные уязвимости

nvd
около 2 месяцев назад

SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0.

github
3 месяца назад

SpiceDB: Caveat structures with nested lists can result in improper cache reuse

4.3 Medium

CVSS3