CVE-2026-45829: ChromaDB Pre-Auth RCE

,

Until a patched version is available, the safest option is to run the Rust-based deployment path and restrict network access to the ChromaDB port to trusted clients only.

Worth noting the failure of Chroma to respond to these findings since February!

1 Like

Not responding to a critical CVE for 2 months, and the ISAC? Yikes.

It’s unfortunate these aren’t tracked better, since this is actually what I want from Bitsight.

Every GRC team at these Enterprises plastered across their site should be keen on this timeline.