← Terug naar overzicht

Chroma version 1.5.9 contains a vulnerability where the HNSW index parameters max_neighbors, ef_construction, and ef_search lack maximum bounds validation in collection-create requests. Unauthenticated attackers can exploit this by supplying arbitrarily large parameter values, leading to server memory exhaustion. The denial of service condition is triggered during index compaction operations. No authentication is required to exploit this vulnerability, significantly increasing its risk. The vulnerability is tracked as CVE-2026-85664 and affects the Rust-based frontend and types components of the Chroma vector database. A GitHub issue and VulnCheck advisory have been published referencing this flaw. Organizations running Chroma 1.5.9 should assess exposure and apply mitigations or patches promptly.

Affected products

  • Chroma 1.5.9

Related CVE's

  • CVE-2026-85664

Categories

  • Database & Storage
  • Emerging Technologies
  • Web Technologies