Home / Companies / Weaviate / Blog / October 2026

October 2026 Summaries

2 posts from Weaviate

Filter
Month: Year:
Post Summaries Back to Blog
No summary generated yet.
Oct 08, 2026 979 words in the original blog post.
Weaviate v1.39.3 fixes a high-severity, CVSS 7.1 credential disclosure vulnerability affecting its Google-backed text2vec-google, multi2vec-google, and generative-google modules in versions earlier than 1.39.3. Unvalidated apiEndpoint values could redirect Vertex AI or Gemini requests to attacker-controlled public hosts while attaching configured Google API keys or broad cloud-platform OAuth tokens, with the most serious path allowing users with ordinary read access to override the endpoint through a GraphQL generative query. The fix validates apiEndpoint values in both module configuration and GraphQL query parameters, while Weaviate Cloud and cloud marketplace customers have already been patched and dedicated customers are being assisted with upgrades. Users unable to upgrade should disable the affected modules or restrict relevant schema-write and query permissions and narrowly scope Google service-account privileges; Weaviate reports no evidence of exploitation. The issue was reported by independent researcher Syed Anas Mohiuddin, and a CVE identifier is pending assignment.
Oct 01, 2026 771 words in the original blog post.