← Vulnerability feed

Vulnerability record · CVE-2023-38975 · published 29 August 2023

CVE-2023-38975: Qdrant classic buffer overflow vulnerability

Qdrant · Qdrant

* Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.

7.5 CVSS 3.1 High EPSS 1.1% · top 36.5% CWE-120 · Classic buffer overflow
7.5CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

* Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://aisec.today/Qdrant-56dd05e12ca94d75a5e798b3fee80fa3 ExploitThird Party Advisory
https://github.com/qdrant/qdrant/issues/2268 ExploitIssue TrackingThird Party Advisory
https://aisec.today/Qdrant-56dd05e12ca94d75a5e798b3fee80fa3 ExploitThird Party Advisory
https://github.com/qdrant/qdrant/issues/2268 ExploitIssue TrackingThird Party Advisory

Track CVE-2023-38975 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-2221Qdrant unrestricted file upload vulnerabilityqdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint…EPSS 1.8%9.8CVE-2024-3078Qdrant path traversal vulnerabilityA vulnerability was found in Qdrant up to 1.6.1/1.7.4/1.8.2 and classified as critical. This issue affects some unknown processing of the file lib/co…EPSS 0.87%9.1CVE-2024-3829Qdrant link following vulnerabilityqdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Attackers can exploit this vulne…EPSS 0.91%8.8CVE-2026-25628Qdrant vulnerabilityQdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger…EPSS 0.64%7.5CVE-2024-3584Qdrant improper input validation vulnerabilityqdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{name}/snapshots/upload` endpoi…EPSS 0.55%5.5CVE-2025-43520Apple OS kernel memory corruption via malicious appA memory corruption flaw (classic buffer overflow) in Apple's kernel was fixed across iOS, iPadOS, macOS, tvOS, visionOS and watchOS. A malicious app…KEVEPSS 0.43%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed9.8CVE-2022-37055D-Link Go-RT-AC750 router buffer overflow in cgibin hnap_mainD-Link Go-RT-AC750 firmware revisions A v101b03 and B v200b02 contain a classic buffer overflow reachable through the cgibin hnap_main handler. The f…KEVEPSS 56%analysed

Source: NIST National Vulnerability Database (record CVE-2023-38975), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.