Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters maxneighbors, efconstruction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server memory and cause denial of service during index compaction.
{
"cwe_ids": [
"CWE-770"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85664.json",
"cna_assigner": "VulnCheck"
}