ChromaDB Python FastAPI server CVE-2026-45829 — pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0); v1.5.9 unpatched at disclosure; Hadrian/HiddenLayer PoC public
cve · item:chromadb-cve-2026-45829-python-fastapi-pre-auth-rce-hidden-l
Coverage timeline
1
first 2026-05-21 → last 2026-05-21
Briefs
1
1 distinct
Sources cited
2
2 hosts
Sections touched
1
trending_vulns
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-05-21CTI Daily Brief — 2026-05-21
Where this entity is cited
- trending_vulns1
Source distribution
- bleepingcomputer.com1 (50%)
- hadrian.io1 (50%)
External references
All cited sources (2)
- hadrian.ioprimaryinlineHadrian Security, 2026-05-19https://hadrian.io/blog/cve-2026-45829----chromadb-python-server-hands-you-rce-before-it-asks-who-you-are
- bleepingcomputer.cominlineBleepingComputer, 2026-05-19https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/
Items in briefs about ChromaDB Python FastAPI server CVE-2026-45829 — pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0); v1.5.9 unpatched at disclosure; Hadrian/HiddenLayer PoC public
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.