Product
Chroma 1.5.9 is vulnerable to an unauthenticated denial-of-service attack due to insufficient bounds validation on HNSW index parameters during collection creation, allowing memory exhaustion.