VYPR
Medium severity6.0NVD Advisory· Published Apr 15, 2026· Updated Apr 23, 2026

CVE-2026-40091

CVE-2026-40091

Description

SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log level info, the startup "configuration" log will include the full datastore DSN, including the plaintext password, inside DatastoreConfig.URI. This issue has been fixed in version 1.51.1. If users are unable to immediately upgrade, they can work around this issue by changing the log level to warn or error.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/authzed/spicedbGo
>= 1.49.0, < 1.51.11.51.1

Affected products

1
  • cpe:2.3:a:authzed:spicedb:*:*:*:*:*:*:*:*
    Range: >=1.49.0,<1.51.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.