{"id":"GHSA-8697-479h-5mfp","summary":"Weaviate denial of service vulnerability","details":"### Impact\nThis vulnerability is a type conversion issue that affects users of Weaviate Server versions 1.20.0 and earlier.\nWho is impacted: Users of Weaviate Server versions 1.20.0 and earlier are impacted by this vulnerability.\n\n### Patches\nA patch has been developed for this vulnerability.\nPatch releases 1.20.6, 1.19.13, and 1.18.6 are fixing this vulnerability in each respective minor version release.\nUsers are strongly recommended to upgrade to one of these patched versions to address the vulnerability.\nKeeping software up-to-date is crucial to avoid security vulnerabilities.\n\n### Workarounds\nThere are no known workarounds to fix or remediate this vulnerability without upgrading.\nUsers must upgrade to a patched version to mitigate the risk.\n\n### References \n* https://github.com/weaviate/weaviate/releases/tag/v1.18.6\n* https://github.com/weaviate/weaviate/releases/tag/v1.19.13\n* https://github.com/weaviate/weaviate/releases/tag/v1.20.6\n","aliases":["CVE-2023-38976","GO-2023-2017"],"modified":"2026-02-04T03:21:54.604954Z","published":"2023-08-22T18:03:13Z","related":["CGA-wphh-9rvv-rpgj"],"database_specific":{"cwe_ids":["CWE-704"],"github_reviewed_at":"2023-08-22T18:03:13Z","github_reviewed":true,"nvd_published_at":null,"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/weaviate/weaviate/security/advisories/GHSA-8697-479h-5mfp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38976"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/issues/3258"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/pull/3431"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/commit/2a7b208d9aca07e28969e3be82689c184ccf9118"},{"type":"PACKAGE","url":"https://github.com/weaviate/weaviate"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/releases/tag/v1.18.6"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/releases/tag/v1.19.13"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/releases/tag/v1.20.6"}],"affected":[{"package":{"name":"github.com/weaviate/weaviate","ecosystem":"Go","purl":"pkg:golang/github.com/weaviate/weaviate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.20.0"},{"fixed":"1.20.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-8697-479h-5mfp/GHSA-8697-479h-5mfp.json"}},{"package":{"name":"github.com/weaviate/weaviate","ecosystem":"Go","purl":"pkg:golang/github.com/weaviate/weaviate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.19.0"},{"fixed":"1.19.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-8697-479h-5mfp/GHSA-8697-479h-5mfp.json"}},{"package":{"name":"github.com/weaviate/weaviate","ecosystem":"Go","purl":"pkg:golang/github.com/weaviate/weaviate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.18.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-8697-479h-5mfp/GHSA-8697-479h-5mfp.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}