Vendor
high
advisory
Authorization Bypass in Chroma via Tenant Isolation Failure
1 TTP 1 CVEChroma versions 1.5.9 and earlier are vulnerable to an authorization bypass allowing authenticated users to access, modify, and delete cross-tenant data by manipulating collection identifiers.
Chroma
vulnerability
authorization-bypass
1t
1c
low
advisory
Denial of Service Vulnerability in Chroma 1.5.9 via HNSW Index Parameters
1 TTP 1 CVEChroma 1.5.9 is vulnerable to an unauthenticated denial-of-service attack due to insufficient bounds validation on HNSW index parameters during collection creation, allowing memory exhaustion.
Chroma
denial-of-service
vulnerability
cve
1t
1c
critical
threat
Unpatched ChromaDB Vulnerability CVE-2026-45829 Allows Remote Code Execution
2 rules 1 TTP 1 CVEAn unpatched pre-authentication remote code execution (RCE) vulnerability, tracked as CVE-2026-45829 and referred to as ChromaToast, in ChromaDB versions 1.0.0 and later allows remote, unauthenticated attackers to execute arbitrary code and leak sensitive information, potentially leading to a server takeover.
ChromaDB >= 1.0.0
chromadb
rce
cve-2026-45829
huggingface
vectordatabase
2r
1t
1c