Weaviate

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-65318

    Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader

    Last Modified: Jul 23, 2026
    Published: Jul 21, 2026

    CVE-2026-65317

    Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass

    Last Modified: Jul 23, 2026
    Published: Jul 21, 2026

    CVE-2026-59093

    Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment

    Last Modified: Jul 06, 2026
    Published: Jul 02, 2026

    CVE-2026-11500

    Weaviate Static API Key client.go validateConfig authorization

    Last Modified: Jun 08, 2026
    Published: Jun 08, 2026

    CVE-2025-67819

    An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process.

    Last Modified: Dec 19, 2025
    Published: Dec 12, 2025
    Items Per Page
    Weaviate Vulnerabilities & Security CVEs | CVE-DB