GHSA-jqpm-wf57-qx5c

Suggest an improvement
Source
https://github.com/advisories/GHSA-jqpm-wf57-qx5c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jqpm-wf57-qx5c/GHSA-jqpm-wf57-qx5c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jqpm-wf57-qx5c
Aliases
Downstream
MINI (16)
Published
2026-06-08T12:30:28Z
Modified
2026-08-18T15:10:46Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Weaviate has an Improper Authorization issue
Details

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. It is stated that the exploitability is difficult. The exploit is publicly available and might be used. Upgrading to version 1.38.0-rc.0 is able to resolve this issue. The identifier of the patch is 40f2cc32279f0f8a51016c3c6870a2c0c808e6c0. You should upgrade the affected component.

Database specific
{
    "cwe_ids":  [
        "CWE-285"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-29T15:41:13Z",
    "nvd_published_at":  "2026-06-08T10:16:32Z",
    "severity":  "LOW"
}
References

Affected packages

Go / github.com/weaviate/weaviate

Package

Name
github.com/weaviate/weaviate
View open source insights on deps.dev
Purl
pkg:golang/github.com/weaviate/weaviate

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.38.0-rc.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jqpm-wf57-qx5c/GHSA-jqpm-wf57-qx5c.json"