CVE-2026-85664
Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server memory and cause denial of service during index compaction.
- Published Sep 4, 2026
- CVSS 8.7 high
- 0.7% chance of exploitation in the next 30 days (EPSS)