<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:56:47.805514+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261768</id>
    <title>EUVD-2026-261768</title>
    <updated>2026-10-06T09:56:47.851226+00:00</updated>
    <content>EUVD-2026-261768</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65111</id>
    <title>fkie_cve-2025-65111</title>
    <updated>2026-10-06T09:56:47.851264+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one side arrows to a different permission). Then SpiceDB may have missing LookupResources results when checking the permission. This only affects LookupResources; other APIs calculate permissionship correctly. The issue is fixed in version 1.47.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-65111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9m7r-g8hg-x3vr</id>
    <title>GHSA-9m7r-g8hg-x3vr — SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results</title>
    <updated>2026-10-06T09:56:47.851298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/authzed/spicedb</p>
<p>### Impact</p>
<p>If your schema includes the following characteristics:</p>
<p>1. You have a permission defined in terms of a union (`+`)
1. That union references the same relation on both sides, but one side arrows to a different permission</p>
<p>Then you might have missing `LookupResources` results when checking the permission. This only affects `LookupResources`; other APIs calculate permissionship correctly.</p>
<p>A small concrete example:</p>
<p>```
relation doer_of_things: user | group#member
permission do_the_thing = doer_of_things + doer_of_things-&gt;admin
```</p>
<p>A CheckPermission on `do_the_thing` will return the correct permissionship, but a LookupResources on `do_the_thing` may miss resources.</p>
<p>#### A Comprehensive Example</p>
<p>If you have a schema with a structure like this:</p>
<p>```
definition special_user {}</p>
<p>definition user {
  relation special_user_mapping: special_user
  permission special_user = special_user_mapping
}
definition group {
   relation member: user
   permission membership = member + member-&gt;special_user
}</p>
<p>definition system {
  relation viewer: user | group#membership
  // This is the problematic permission
  permission view = viewer + viewer-&gt;special_user
}
```</p>
<p>And these relationships:
```
system:somesystem#viewer@group:somegroup#membership
group:somegroup#member@user:someuser1
user:someuser1#special_user_mapping@special_user:specialuser
```</p>
<p>And you call LookupResources with:
```
subject_type: user
subject_id: someuser1
permission: view
resource_type: system
```</p>
<p>You would expec…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9m7r-g8hg-x3vr"/>
  </entry>
</feed>
