-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from improper context management in parallelized dispatch operations. The pull request #1397 specifically modified context handling in reachableresources.go and lookupresources.go to fix premature cancellation. The original implementation's context management via limit tracking caused early termination of resource lookup operations, leading to partial results. These functions directly implement the vulnerable pattern described in the advisory where cancellation errors were ignored during parallel processing.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/authzed/spicedb | go | = 1.22.0 | 1.22.2 |
Ongoing coverage of React2Shell