Skip to content

Weaviate security advisories

4 advisories · 2 critical or high in 12 months · latest Jun 8

4 advisories

DateAdvisory
Jun 8Weaviate has an Improper Authorization issue
CVE-2026-11500Low5.0fixed in 1.38.0-rc.0
Dec 122025Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
CVE-2025-67818Highfixed in 1.30.20, 1.31.19, 1.32.16, 1.33.4
Dec 122025Weaviate OSS has path traversal vulnerability via the Shard Movement API
CVE-2025-67819Highfixed in 1.30.20, 1.31.19, 1.32.16, 1.33.4
Aug 222023Weaviate denial of service vulnerability
CVE-2023-38976High7.5fixed in 1.18.6, 1.19.13, 1.20.6
About Weaviate

The open-source AI-native vector database.

Packages watched: github.com/weaviate/weaviate (Go).

Weaviate elsewhere on fru.dev: Releases · Repos

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.