Skip to content

qdrant

v1.18.2 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Vector Databases
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai-search ai-search-engine embeddings-similarity hnsw hybrid-search image-search
+12 more
knn-algorithm machine-learning mlops nearest-neighbor-search neural-search recommender-system search search-engine search-engines similarity-search vector-db vector-search-engine

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates https, Bug Fixes, and Change log across a mixed release.

Full changelog

Change log

Improvements

  • https://github.com/qdrant/qdrant/pull/9282 - Log slow operations during shard WAL recovery
  • https://github.com/qdrant/qdrant/pull/9137 - Clear cache of ID tracker after building a segment
  • https://github.com/qdrant/qdrant/pull/9138 - Don't rebuild payload index if changing on_disk flag

Bug Fixes

  • https://github.com/qdrant/qdrant/pull/9285 - Fix potential infinite loop in optimizer when using multi vectors with prevent_unoptimized
  • https://github.com/qdrant/qdrant/pull/9217 - Clean up unfinished segment optimizations on cancellation, don't load them on restart
  • https://github.com/qdrant/qdrant/pull/9260 - Fix MatchAny with an empty list being rejected on integer index
  • https://github.com/qdrant/qdrant/pull/9239 - Add timeout to shard snapshot streaming endpoint, drop connections not actively read from
  • https://github.com/qdrant/qdrant/pull/9215 - Fix abort transfer with resharding not being idempotent
  • https://github.com/qdrant/qdrant/pull/9237 - Fix reporting old progress in new snapshot transfers
  • https://github.com/qdrant/qdrant/pull/9226 - Fix WAL lock error on Android platforms

Security

  • https://github.com/qdrant/qdrant/pull/9254 - Fix REST auth whitelist bypass on specially crafted paths, resolve route before authorizing
  • https://github.com/qdrant/qdrant/pull/9268 - Fix out of bound heap read with malicious snapshot by rejecting incorrect length

Security Fixes

  • Fix REST auth whitelist bypass on specially crafted paths (resolve route before authorizing)
  • Reject malformed snapshots to prevent out‑of‑bounds heap reads

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track qdrant

Get notified when new releases ship.

Sign up free

About qdrant

Qdrant - High-performance, massive-scale Vector Database and Vector Search Engine for the next generation of AI. Also available in the cloud https://cloud.qdrant.io/

All releases →

Related context

Related tools

Earlier breaking changes

  • v1.18.0 Fully remove RocksDB storage backend support

Beta — feedback welcome: [email protected]