Skip to content
Noroxi

authzed records

13 published records for vendor authzed.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

13 records
  • Integer overflow in chunking helper causes dispatching to miss elements or panic

    CriticalCVSS 9.1No exploitEPSS 0%

    authzed · spicedbMar 1, 2024

  • Lookup operations do not take into account wildcards in SpiceDB

    HighCVSS 8.1No exploitEPSS 1%

    authzed · spicedbJan 11, 2022

  • SpiceDB binding metrics port to untrusted networks and can leak command-line flags

    HighCVSS 7.5No exploitEPSS 1%

    authzed · spicedbApr 14, 2023

  • `SPICEDB_DATASTORE_CONN_URI` is leaked when URI cannot be parsed

    MediumCVSS 6.5No exploitEPSS 0%

    authzed · spicedbOct 31, 2023

  • LookupResources may return partial results in spicedb

    MediumCVSS 5.3No exploitEPSS 0%

    authzed · spicedbJun 26, 2023

  • Permissions processing error in spacedb

    MediumCVSS 5.3No exploitEPSS 0%

    authzed · spicedbJun 20, 2024

  • SpiceDB checks involving relations with caveats can result in no permission when permission is expected

    MediumCVSS 5.3No exploitEPSS 0%

    authzed · spicedbJun 6, 2025

  • Multiple caveats on resources of the same type can result in no permission when permission is expected

    MediumCVSS 5.3No exploitEPSS 0%

    authzed · spicedbSep 18, 2024

  • SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used

    MediumCVSS 4.3No exploitEPSS 1%

    authzed · spicedbApr 10, 2024

  • SpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logs

    MediumCVSS 4.4No exploitEPSS 0%

    authzed · spicedbApr 15, 2026

  • SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results

    LowCVSS 2.9No exploitEPSS 0%

    authzed · spicedbNov 21, 2025

  • SpiceDB's WriteRelationships fails silently if payload is too big

    LowCVSS 2.7No exploitEPSS 0%

    authzed · spicedbNov 10, 2025

  • SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not

    LowCVSS 2.4No exploitEPSS 0%

    authzed · spicedbOct 14, 2024