Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45832

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

A flaw was found in ChromaDB. All V1 collection-level endpoints in the Python project pass null values for tenant and database to the authorization layer. This allows a remote attacker to bypass authorization controls by utilizing these V1 endpoints. The primary consequence is unauthorized access, potentially leading to high impact on confidentiality and integrity of data.

Отчет

This flaw is a post-authentication tenant-isolation bypass on ChromaDB’s V1 API — it does not grant unauthenticated access and does not enable code execution. RH AI products bundle a vulnerable chromadb version but do not run the Chroma Python FastAPI server as the default product API (AutoRAG uses Milvus/pgvector; RHEL AI bootc uses chromadb as a library).

Меры по смягчению последствий

To mitigate this issue, restrict network access to the ChromaDB instance to trusted clients only. Configure firewall rules to limit inbound connections to the ports used by ChromaDB. This will reduce the attack surface by preventing unauthorized remote access to the vulnerable V1 collection-level endpoints. After applying firewall rules, ensure to reload or restart the firewall service for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Will not fix
Red Hat OpenShift AI (RHOAI)rhoai/odh-autorag-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-551
https://bugzilla.redhat.com/show_bug.cgi?id=2488411chromadb: ChromaDB: Authorization bypass in V1 collection-level endpoints

EPSS

Процентиль: 21%
0.00284
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

CVSS3: 8.8
github
около 2 месяцев назад

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

EPSS

Процентиль: 21%
0.00284
Низкий

8.1 High

CVSS3