chromadb has 3 CVEs on record. The busiest recent month was June 2026 with 3. The median CVSS is 8.8 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
Products
- chromadb 3
3
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-45833CriticalChromaDB has a code injection vulnerability64CVE-2026-45831High· 8.8ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to48CVE-2026-45830High· 8.8ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection48
chromadb vulnerabilities
CVEs affecting chromadb, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-45831High· 8.8ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
▾ Twilightchromadb · chromadbEPSS 0.24%via OSV
CVE-2026-45833CriticalPoCChromaDB has a code injection vulnerability
ChromaDB has a code injection vulnerability
▾ Abyssalchromadb · chromadbEPSS 0.34%via OSV
CVE-2026-45830High· 8.8ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
▾ Twilightchromadb · chromadbEPSS 0.34%via OSV