Executive brief
SpiceDB is a database used to manage and check user permissions within applications. A flaw in how it searches for resources means that in certain complex configurations, it may fail to list all the items a user actually has permission to access. While this does not allow unauthorized access, it can cause applications to behave incorrectly by hiding data or options that should be visible to the user.
Technical details
A vulnerability in SpiceDB's reachability graph and query planner causes incomplete results in the LookupResources API. The issue occurs when a permission is defined as a union (+) where both sides reference the same relation, but one side uses an arrow (->) to reference a different permission. This configuration causes the engine to skip necessary entrypoint computations in the reachability graph. While LookupResources may fail to return all valid resources, the CheckPermission API remains unaffected and correctly validates access. The issue is resolved in version 1.47.1 by fixing the entrypoint computation logic.
Affected products
- Authzed SpiceDB < 1.47.1
Timeline
- 2025-11-20: patched: Fix committed to repository
- 2025-11-21: advisory: GitHub Advisory published