Authorization Schema Vulnerability in SpiceDB by Authzed
CVE-2025-64529
What is CVE-2025-64529?
SpiceDB, a security-critical application permissions database, has a vulnerability in versions prior to 1.45.2. If users employ the exclusion operator in their authorization schema and configure their server with --write-relationships-max-updates-per-call exceeding 6500, they may encounter an issue where the WriteRelationships call unexpectedly returns a successful response despite the existence of a failure. This can lead to incorrect permission checks when these relationships are read. To mitigate the risk, it is advised to downgrade the --write-relationships-max-updates-per-call setting to 1000, or upgrade to version 1.45.2, which includes the necessary patch.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
spicedb < 1.45.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
