Weaviate is a vector database and semantic search platform whose vulnerability footprint concentrates in its core product with observed weaknesses centered on path-traversal conditions and assertion-handling issues in its data-access and file-management layers. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weaviate over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59093HIGH Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The assignRoleToUser and assignRoleTo | Jul 2, 2026 | 8.8 | 38 | NO | NO |
CVE-2025-67818HIGH An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or us | Dec 12, 2025 | 7.2 | 24 | NO | NO |
CVE-2023-38976HIGH An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function. | Aug 21, 2023 | 7.5 | 21 | NO | NO |
CVE-2025-67819MEDIUM An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a | Dec 12, 2025 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weaviate.
Media articles that mention a CVE ID that affects a product developed by Weaviate — matched by CVE ID, not by vendor name.