Skip to content

Chroma security advisories

4 advisories across Chroma

Company profile
DateAdvisory
Jun 12ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
CVE-2026-45830High8.8no fix yet
Jun 12ChromaDB has a code injection vulnerability
CVE-2026-45833Criticalno fix yet
Jun 12ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
CVE-2026-45831High8.8no fix yet
May 18ChromaDB Python project has a pre-authentication code injection vulnerability
CVE-2026-45829Criticalno fix yet
About Chroma

Elsewhere on fru.dev: Releases

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.