The number and severity of CVEs published that impact products developed by Trychroma over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45833HIGH A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious | Jun 12, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-45832HIGH All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls | Jun 12, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-45830HIGH A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in an | Jun 12, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-45831HIGH The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never che | Jun 12, 2026 | 8.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trychroma.
Media articles that mention a CVE ID that affects a product developed by Trychroma — matched by CVE ID, not by vendor name.