High severity7.5NVD Advisory· Published Sep 4, 2026
CVE-2026-85664
CVE-2026-85664
Description
Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server memory and cause denial of service during index compaction.
Affected products
1- Range: <1.5.9
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.