chroma-core has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.8 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- chroma 2
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-92782High· 8.1Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier57CVE-2026-85664High· 7.5Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests41
chroma-core vulnerabilities
CVEs affecting chroma-core, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-92782High· 8.1PoCChroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier
Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, a…
▾ Midnightchroma-core · chromaEPSS 0.25%via NVD
CVE-2026-85664High· 7.5Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests
Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server…
▾ Twilightchroma-core · chromaEPSS 0.37%via NVD