2026-09-30
Weaviate patches high-severity credential leak bug in Google-backed modules
Weaviate, per weaviate.io, fixed a high-severity flaw in v1.39.3 where an unvalidated apiEndpoint setting in its Google-backed modules could redirect outbound requests, and a user's Google credential, to an arbitrary host; a CVE is pending. Weaviate says Cloud and Marketplace customers were patched automatically, with Enterprise and Dedicated customers being notified or upgraded.
Source. weaviate.io