{"id":"CVE-2025-65111","aliases":["GHSA-9m7r-g8hg-x3vr","GO-2025-4151"],"url":"https://o3.security/vulnerability/CVE-2025-65111","summary":"SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results","details":"SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one side arrows to a different permission). Then SpiceDB may have missing LookupResources results when checking the permission. This only affects LookupResources; other APIs calculate permissionship correctly. The issue is fixed in version 1.47.1.","published":"2025-11-21T22:02:52.563Z","modified":"2026-08-08T03:48:15.745006395Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/authzed/spicedb","fixedVersion":"1.47.1"}],"fix":{"url":"https://github.com/authzed/spicedb/commit/8c2edbe1e7bd3851fa2138f4cc344bfde986dcf2","label":"authzed/spicedb@8c2edbe"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65111.json"},{"type":"ADVISORY","url":"https://github.com/authzed/spicedb/security/advisories/GHSA-9m7r-g8hg-x3vr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65111"},{"type":"FIX","url":"https://github.com/authzed/spicedb/commit/8c2edbe1e7bd3851fa2138f4cc344bfde986dcf2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:15.745006395Z"}}