CVE-2025-64529 is a medium-severity vulnerability affecting SpiceDB versions prior to 1.45.2, an open-source database for managing application permissions. Specifically, it impacts configurations using the exclusion operator, a high `--write-relationships-max-updates-per-call` value, and large WriteRelationships payloads exceeding datastore limits. This can lead to incorrect permission checks due to silently failed write operations, despite a successful response. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network attack vector with low attack complexity and no user interaction required. The potential impact is limited to integrity and availability, as incorrect permissions could be granted or denied. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.45.2CPE matchmatch criteria | cpe:2.3:a:authzed:spicedb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.