StackRadar

CVE-2026-45833

Critical

Advisory

Published 12 Jun 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.4
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
None
affected package

ChromaDB has a code injection vulnerability

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
chromadbpypi0.5.0, 0.5.7, 0.5.20, 0.5.23+2 moreno fix listed8
OSV records
GHSA-36p7-vc44-83pf
Also known as
PYSEC-2026-3814

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
langgenius/dify-api:1.16.1dcefa5f7c47c
chromadb@0.5.20
no fix listed

Open the chart page →

22,002
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
chromadb@0.5.0
no fix listed

Open the chart page →

20,403
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
langflowai/langflow:latest65796601f3fc
chromadb@1.5.9
no fix listed

Open the chart page →

3,980
langflow-runtimelangflow0.1.11 of 1See more

langflow-runtime langflow 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
langflowai/langflow:latest65796601f3fc
chromadb@1.5.9
no fix listed

Open the chart page →

144
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
chromadb@0.5.23
no fix listed

Open the chart page →

58,897
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
chromadb@0.5.20
no fix listed

Open the chart page →

19,224
langflowhelmforgeVerified publisher2.0.01 of 1See more

langflow helmforge 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
langflowai/langflow:1.12.065796601f3fc
chromadb@1.5.9
no fix listed

Open the chart page →

144
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
yetiplatform/yeti:2.9.09bcbe2650a14
chromadb@1.5.7
no fix listed

Open the chart page →

71,208
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
chromadb@1.5.7
no fix listed

Open the chart page →

6,583
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45833.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
chromadb@0.5.7
no fix listed

Open the chart page →

5,350

Container images carrying it

8 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
langflowai/langflow:1.12.0:latest65796601f3fc
chromadb@1.5.9
no fix listed
3
langgenius/dify-api:1.0.0066035f93856
chromadb@0.5.20
no fix listed
1
langgenius/dify-api:1.16.1dcefa5f7c47c
chromadb@0.5.20
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
chromadb@0.5.0
no fix listed
1
opea/web-retriever-chroma:1.0fe08165d7770
chromadb@0.5.7
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
chromadb@0.5.23
no fix listed
1
yetiplatform/yeti:2.9.09bcbe2650a14
chromadb@1.5.7
no fix listed
1
yetiplatform/yeti:latest9c3006cedcca
chromadb@1.5.7
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.