Executive brief
SpiceDB, a database used for managing application permissions, may inadvertently leak sensitive database credentials in its system logs. When the application starts with standard logging enabled, it writes the full connection string—including plaintext passwords—to the log files. An attacker with access to these logs could use the credentials to gain unauthorized access to the underlying data store, potentially leading to data theft or service disruption.
Technical details
SpiceDB versions 1.49.0 through 1.51.0 contain a sensitive information leak (CWE-532) in the startup logging routine. When the log level is set to 'info', the 'configuration' log entry includes the full DatastoreConfig.URI, which contains the Data Source Name (DSN) and any associated plaintext passwords. This vulnerability requires local access to the log files or access to a log aggregation service. An attacker with sufficient privileges to read these logs can extract database credentials to compromise the backend datastore. The issue is resolved in version 1.51.1; a temporary workaround is to set the log level to 'warn' or 'error'.
Affected products
- Authzed SpiceDB >= 1.49.0, <= 1.51.0
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory
- 2026-04-14: patched: v1.51.1 released