Weaviate has 4 CVEs on record between 2023 and 2026. 2 were published in the last 90 days. The median CVSS is 8.1 (high). Most affected products: Verba (2), github.com/weaviate/weaviate (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 1
Weakness classes
Products
- Verba 2
- github.com/weaviate/weaviate 2
Worst active — by depth score
CVE-2026-65318High· 8.6Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader59CVE-2026-65317High· 8.6Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass59CVE-2023-38976High· 7.5Weaviate denial of service vulnerability42CVE-2026-11500Medium· 5.0Weaviate has an Improper Authorization issue28
Weaviate vulnerabilities
CVEs affecting Weaviate, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-65317High· 8.6PoCVerba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by suppl…
CVE-2026-65318High· 8.6PoCVerba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled UR…
CVE-2026-11500Medium· 5.0Weaviate has an Improper Authorization issue
Weaviate has an Improper Authorization issue
CVE-2023-38976High· 7.5Weaviate denial of service vulnerability
Weaviate denial of service vulnerability