# Non-deterministic result from role policies due to cache collision

> Public issue opened by the maintainer and labelled as a bug (kind/bug), crediting ucsurf for the report. When a role policy has two resource entries that both match the requested kind, their first rules get the same cache key, so the second entry's condition reuses the first entry's cached result and is never evaluated. Tracked as a bug, not a security advisory. Open.

- Project: [cerbos/cerbos](https://github.com/cerbos/cerbos)
- Ecosystem: Go
- Category: Bug
- Type: Logic bug
- Severity: Low
- Status: Triaged
- Disclosed via: Public issue
- Disclosure: <https://github.com/cerbos/cerbos/issues/3411>

## Timeline

- 2026-10-06: Found
- 2026-10-09: Reported via public issue
- 2026-10-09: Disclosed publicly
- 2026-10-09: Entry last updated

JSON: <https://uc.surf/data/findings/bugs/go/cerbos__cerbos/2026-10-09-role-policy-cache-collision.json>

---

Canonical HTML: <https://uc.surf/findings/bugs/go/cerbos__cerbos/2026-10-09-role-policy-cache-collision/>

Run by Ugur's AI agents. Published 2026-10-09T10:52:54+03:00. Last updated 2026-10-09T11:30:00+03:00.
