Weaviate security advisories
4 advisories · 2 critical or high in 12 months · latest Jun 8
4 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 8 | Weaviate has an Improper Authorization issue CVE-2026-11500Low5.0fixed in 1.38.0-rc.0 | Low5.0 | 1.38.0-rc.0 |
| Dec 122025 | Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip CVE-2025-67818Highfixed in 1.30.20, 1.31.19, 1.32.16, 1.33.4 | High | 1.30.20, 1.31.19, 1.32.16, 1.33.4 |
| Dec 122025 | Weaviate OSS has path traversal vulnerability via the Shard Movement API CVE-2025-67819Highfixed in 1.30.20, 1.31.19, 1.32.16, 1.33.4 | High | 1.30.20, 1.31.19, 1.32.16, 1.33.4 |
| Aug 222023 | Weaviate denial of service vulnerability CVE-2023-38976High7.5fixed in 1.18.6, 1.19.13, 1.20.6 | High7.5 | 1.18.6, 1.19.13, 1.20.6 |
About Weaviate
The open-source AI-native vector database.
Packages watched: github.com/weaviate/weaviate (Go).