CVE-2026-46668

Description

A flaw was found in SpiceDB, an open-source database system for managing application permissions. This vulnerability occurs due to improper cache reuse when processing caveat structures that contain nested lists. This could lead to unexpected behavior or a low impact on confidentiality, potentially resulting in minor information disclosure.

Statement

Red Hat ships SpiceDB as a dependency in the Management Platform service (cloud.redhat.com). The vulnerability involves improper cache reuse when processing caveat structures with nested lists, which could lead to minor information disclosure. The affected version range is 1.15.0 to before 1.52.0.

Mitigation

Avoid using caveat structures with nested lists in SpiceDB permission definitions until the fix (v1.52.0) is applied. Alternatively, update SpiceDB to version 1.52.0 or later.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Unexpected State

Frequently Asked Questions

Want to get errata notifications? Sign up here.