chromadb vulnerabilities
CVEs whose affected-version data names the chromadb package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-45831High· 8.8ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
▾ Twilightchromadb · chromadbEPSS 0.24%via OSV
CVE-2026-45833CriticalPoCChromaDB has a code injection vulnerability
ChromaDB has a code injection vulnerability
▾ Abyssalchromadb · chromadbEPSS 0.34%via OSV
CVE-2026-45830High· 8.8ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
▾ Twilightchromadb · chromadbEPSS 0.34%via OSV