<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:38:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-231350</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-231350</link>
      <description>EUVD-2026-231350</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-231350</guid>
    </item>
    <item>
      <title>fkie_cve-2024-27101</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27101</link>
      <description>&lt;p&gt;SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic.  Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject type is affected by this problem.  The CheckPermission, BulkCheckPermission, and LookupSubjects API methods are affected. This vulnerability is fixed in 1.29.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic.  Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject type is affected by this problem.  The CheckPermission, BulkCheckPermission, and LookupSubjects API methods are affected. This vulnerability is fixed in 1.29.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-27101</guid>
    </item>
    <item>
      <title>GHSA-h3m7-rqc4-7h9p — Integer overflow in chunking helper causes dispatching to miss elements or panic</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h3m7-rqc4-7h9p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/authzed/spicedb&lt;/p&gt;
&lt;p&gt;Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject type is affected by this problem.&lt;/p&gt;
&lt;p&gt;The issue may also lead to a panic rendering the server unavailable&lt;/p&gt;
&lt;p&gt;The following API methods are affected:
- [CheckPermission](https://buf.build/authzed/api/docs/main:authzed.api.v1#authzed.api.v1.PermissionsService.CheckPermission)
- [BulkCheckPermission](https://buf.build/authzed/api/docs/main:authzed.api.v1#authzed.api.v1.ExperimentalService.BulkCheckPermission)
- [LookupSubjects](https://buf.build/authzed/api/docs/main:authzed.api.v1#authzed.api.v1.PermissionsService.LookupSubjects)&lt;/p&gt;
&lt;p&gt;#### Impact&lt;/p&gt;
&lt;p&gt;Permission checks that are expected to be allowed are instead denied, and lookup subjects will return fewer subjects than expected.&lt;/p&gt;
&lt;p&gt;#### Workarounds&lt;/p&gt;
&lt;p&gt;There is no workaround other than making sure that the SpiceDB cluster does not have very wide relations, with the maximum value being the maximum value of an 16-bit unsigned integer&lt;/p&gt;
&lt;p&gt;#### Remediations&lt;/p&gt;
&lt;p&gt;- AuthZed Dedicated customers: No action. AuthZed has upgraded all deployments.
- AuthZed Serverless customers: No Action. AuthZed has upgraded all deployments.
- AuthZed Enterprise customers: Upgrade to [v1.29.2-hotfix-enterprise.v1.hotfix.v1](https://github.com/authzed-enterprise/src/pkgs/container/spicedb-enterprise/182719614?tag=v1.29.2-hotfix-enterprise.v1.hotfix.v1)
 - Open Source users: Upgrade to v1.29.2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/authzed/spicedb&lt;/p&gt;
&lt;p&gt;Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject type is affected by this problem.&lt;/p&gt;
&lt;p&gt;The issue may also lead to a panic rendering the server unavailable&lt;/p&gt;
&lt;p&gt;The following API methods are affected:
- [CheckPermission](https://buf.build/authzed/api/docs/main:authzed.api.v1#authzed.api.v1.PermissionsService.CheckPermission)
- [BulkCheckPermission](https://buf.build/authzed/api/docs/main:authzed.api.v1#authzed.api.v1.ExperimentalService.BulkCheckPermission)
- [LookupSubjects](https://buf.build/authzed/api/docs/main:authzed.api.v1#authzed.api.v1.PermissionsService.LookupSubjects)&lt;/p&gt;
&lt;p&gt;#### Impact&lt;/p&gt;
&lt;p&gt;Permission checks that are expected to be allowed are instead denied, and lookup subjects will return fewer subjects than expected.&lt;/p&gt;
&lt;p&gt;#### Workarounds&lt;/p&gt;
&lt;p&gt;There is no workaround other than making sure that the SpiceDB cluster does not have very wide relations, with the maximum value being the maximum value of an 16-bit unsigned integer&lt;/p&gt;
&lt;p&gt;#### Remediations&lt;/p&gt;
&lt;p&gt;- AuthZed Dedicated customers: No action. AuthZed has upgraded all deployments.
- AuthZed Serverless customers: No Action. AuthZed has upgraded all deployments.
- AuthZed Enterprise customers: Upgrade to [v1.29.2-hotfix-enterprise.v1.hotfix.v1](https://github.com/authzed-enterprise/src/pkgs/container/spicedb-enterprise/182719614?tag=v1.29.2-hotfix-enterprise.v1.hotfix.v1)
 - Open Source users: Upgrade to v1.29.2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h3m7-rqc4-7h9p</guid>
    </item>
    <item>
      <title>gsd-2024-27101</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-27101</link>
      <description>gsd-2024-27101</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-27101</guid>
    </item>
  </channel>
</rss>
