Beveiligingsadvies

CVE-2026-85664

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-04 14:32:20
Laatst bijgewerkt 2026-09-04 14:32:20
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server memory and cause denial of service during index compaction.