NIXPKGS-2026-1123
GitHub issue
published on
Permalink
CVE-2026-40091
6.0 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): HIGH
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
3 packages
- tree-sitter-grammars.tree-sitter-spicedb
- python314Packages.tree-sitter-grammars.tree-sitter-spicedb
- python313Packages.tree-sitter-grammars.tree-sitter-spicedb
- @LeSuisse accepted
- @LeSuisse published on GitHub
SpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logs
SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log level info, the startup "configuration" log will include the full datastore DSN, including the plaintext password, inside DatastoreConfig.URI. This issue has been fixed in version 1.51.1. If users are unable to immediately upgrade, they can work around this issue by changing the log level to warn or error.
References
-
https://github.com/authzed/spicedb/security/advisories/GHSA-jf4f-rr2c-9m58 x_refsource_CONFIRM
-
https://github.com/authzed/spicedb/releases/tag/v1.51.1 x_refsource_MISC
Affected products
spicedb
- ==>= 1.49.0, < 1.51.1
Matching in nixpkgs
Ignored packages (3)
pkgs.tree-sitter-grammars.tree-sitter-spicedb
Tree-sitter grammar for spicedb
-
nixos-unstable 0-unstable-2024-02-08
- nixpkgs-unstable 0-unstable-2024-02-08
- nixos-unstable-small 0-unstable-2024-02-08
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-spicedb
Python bindings for tree-sitter-spicedb
-
nixos-unstable 0+unstable20240208
- nixpkgs-unstable 0+unstable20240208
- nixos-unstable-small 0+unstable20240208
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-spicedb
Python bindings for tree-sitter-spicedb
-
nixos-unstable 0+unstable20240208
- nixpkgs-unstable 0+unstable20240208
- nixos-unstable-small 0+unstable20240208
Package maintainers
-
@thoughtpolice Austin Seipp <aseipp@pobox.com>
-
@squat squat