{"id":"GHSA-4vrg-r928-h5vv","summary":"SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected","details":"### Impact\n Under concurrency, `CheckPermission` and `CheckBulkPermissions` can return `PERMISSIONSHIP_HAS_PERMISSION` for a (resource, permission, subject) whose correct answer is   `PERMISSIONSHIP_CONDITIONAL_PERMISSION`. \n\n You are impacted if **all** of the following hold:\n\n  1. Your schema has a permission combining relations with an intersection or exclusion, where a subject reaches it through a caveated branch and a non-caveated branch. For example:\n\n```zed\n  definition user {}\n\n  caveat some_caveat(somecondition int) { somecondition == 42 }\n\n  definition document {\n    relation reader: user | user with some_caveat\n    relation writer: user\n    relation banned: user\n    permission has_permission = (reader & writer) - banned\n  }\n```\n\n  2. A subject reaches the permission via the caveated edge:\n\n```\n  document:firstdoc#reader@user:caveatedreader[some_caveat]\n  document:firstdoc#writer@user:caveatedreader\n```\n  3. Your workload issues `LookupResources` with a `context` request parameter, concurrently with `CheckPermission/CheckBulkPermissions` for the same subject/resource, and\n  4. The dispatch result cache is enabled.\n  \nWhen all of the above are true, there is an intermittent window in which:\n\n`CheckPermission(document:firstdoc, has_permission, user:caveatedreader)` → HAS_PERMISSION (incorrect; should be CONDITIONAL_PERMISSION)\n\n`CheckPermission(document:firstdoc, has_permission, user:caveatedreader, context = {\"somecondition\": 41})` → HAS_PERMISSION (incorrect; should be NO_PERMISSION)\n\n### Patches\n\nv1.54.0\n\n### Workarounds\nDisable the dispatch result cache (`ClusterDispatchCacheConfig` and `DispatchCacheConfig`)","aliases":["CVE-2026-55866","GO-2026-5133"],"modified":"2026-06-25T18:56:25.951043214Z","published":"2026-06-19T21:42:12Z","database_specific":{"cwe_ids":["CWE-863"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-06-19T21:42:12Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/authzed/spicedb/security/advisories/GHSA-4vrg-r928-h5vv"},{"type":"PACKAGE","url":"https://github.com/authzed/spicedb"}],"affected":[{"package":{"name":"github.com/authzed/spicedb","ecosystem":"Go","purl":"pkg:golang/github.com/authzed/spicedb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.34.0"},{"fixed":"1.54.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4vrg-r928-h5vv/GHSA-4vrg-r928-h5vv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}