{"id":"GHSA-jf4f-rr2c-9m58","summary":"SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs","details":"### Impact\nWhen SpiceDB starts with log level `info`, the startup `\"configuration\"` log will include the full datastore DSN, including the plaintext password, inside `DatastoreConfig.URI`.\n\n### Patches\nv1.51.1\n\n### Workarounds\nChange the log level to `warn` or `error`.","aliases":["CVE-2026-40091","GO-2026-5465"],"modified":"2026-06-25T23:11:22.912620274Z","published":"2026-04-14T22:33:06Z","database_specific":{"github_reviewed_at":"2026-04-14T22:33:06Z","nvd_published_at":"2026-04-15T04:17:46Z","cwe_ids":["CWE-532"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/authzed/spicedb/security/advisories/GHSA-jf4f-rr2c-9m58"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40091"},{"type":"PACKAGE","url":"https://github.com/authzed/spicedb"},{"type":"WEB","url":"https://github.com/authzed/spicedb/releases/tag/v1.51.1"}],"affected":[{"package":{"name":"github.com/authzed/spicedb","ecosystem":"Go","purl":"pkg:golang/github.com/authzed/spicedb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.49.0"},{"fixed":"1.51.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jf4f-rr2c-9m58/GHSA-jf4f-rr2c-9m58.json","last_known_affected_version_range":"\u003c= 1.51.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"}]}