Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9m7r-g8hg-x3vr | SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results |
Wed, 31 Dec 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:authzed:spicedb:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Authzed
Authzed spicedb |
|
| Vendors & Products |
Authzed
Authzed spicedb |
Fri, 21 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one side arrows to a different permission). Then SpiceDB may have missing LookupResources results when checking the permission. This only affects LookupResources; other APIs calculate permissionship correctly. The issue is fixed in version 1.47.1. | |
| Title | SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results | |
| Weaknesses | CWE-277 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-24T17:50:51.445Z
Reserved: 2025-11-17T20:55:34.694Z
Link: CVE-2025-65111
Updated: 2025-11-24T17:18:16.001Z
Status : Analyzed
Published: 2025-11-21T22:16:33.697
Modified: 2025-12-31T13:41:21.827
Link: CVE-2025-65111
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:08:14Z
Github GHSA