Junglewise Threat Intelligence

CVE-2026-40091: Authzed SpiceDB sensitive information leak in startup logs

CVE-2026-40091 · Severity: medium · CVSS 6 · Published 2026-04-14

Technologies: Authzed SpiceDB, github.com/authzed/spicedb (Go). Vendors: Authzed, Go.

Executive brief

SpiceDB, a database used for managing application permissions, may inadvertently leak sensitive database credentials in its system logs. When the application starts with standard logging enabled, it writes the full connection string—including plaintext passwords—to the log files. An attacker with access to these logs could use the credentials to gain unauthorized access to the underlying data store, potentially leading to data theft or service disruption.

Technical details

SpiceDB versions 1.49.0 through 1.51.0 contain a sensitive information leak (CWE-532) in the startup logging routine. When the log level is set to 'info', the 'configuration' log entry includes the full DatastoreConfig.URI, which contains the Data Source Name (DSN) and any associated plaintext passwords. This vulnerability requires local access to the log files or access to a log aggregation service. An attacker with sufficient privileges to read these logs can extract database credentials to compromise the backend datastore. The issue is resolved in version 1.51.1; a temporary workaround is to set the log level to 'warn' or 'error'.

Affected products

  • Authzed SpiceDB >= 1.49.0, <= 1.51.0

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory
  • 2026-04-14: patched: v1.51.1 released

References

Related threats