LIVE · cybersecurity feed
Live wire
vendor

Trychroma

4 CVEs published in the last four months. Exploited flaws first.

Critical0
High4
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-458308.8highchromadbA lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authentica86d ago
CVE-2026-458318.8highchromadbThe SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python proje86d ago
CVE-2026-458328.8highchromadbAll V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the author86d ago
CVE-2026-458338.8highchromadbA code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated a86d ago

Filter the full tracker by Trychroma