{"id":"GO-2026-6140","summary":"Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate","details":"Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate","aliases":["CVE-2026-11500","GHSA-jqpm-wf57-qx5c"],"modified":"2026-08-18T15:00:14.475736906Z","published":"2026-08-18T14:32:29Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6140","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jqpm-wf57-qx5c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11500"},{"type":"FIX","url":"https://github.com/weaviate/weaviate/commit/40f2cc32279f0f8a51016c3c6870a2c0c808e6c0"},{"type":"REPORT","url":"https://github.com/weaviate/weaviate/issues/11392"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/releases/tag/v1.38.0-rc.0"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-11500"},{"type":"WEB","url":"https://vuldb.com/submit/835080"},{"type":"WEB","url":"https://vuldb.com/vuln/369120"},{"type":"WEB","url":"https://vuldb.com/vuln/369120/cti"}],"affected":[{"package":{"name":"github.com/weaviate/weaviate","ecosystem":"Go","purl":"pkg:golang/github.com/weaviate/weaviate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.38.0-rc.0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6140.json"}}],"schema_version":"1.9.0"}