CVE-2026-46668
Description
A flaw was found in SpiceDB, an open-source database system for managing application permissions. This vulnerability occurs due to improper cache reuse when processing caveat structures that contain nested lists. This could lead to unexpected behavior or a low impact on confidentiality, potentially resulting in minor information disclosure.
Statement
Red Hat ships SpiceDB as a dependency in the Management Platform service (cloud.redhat.com). The vulnerability involves improper cache reuse when processing caveat structures with nested lists, which could lead to minor information disclosure. The affected version range is 1.15.0 to before 1.52.0.
Mitigation
Avoid using caveat structures with nested lists in SpiceDB permission definitions until the fix (v1.52.0) is applied. Alternatively, update SpiceDB to version 1.52.0 or later.
Understanding the Weakness (CWE)
Integrity
Technical Impact: Unexpected State
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.