ADVISORY UNAUTH-2026-0009
TYPE exposure-class
PRODUCT Qdrant
SEVERITY HIGH
Qdrant gRPC data plane (:6334) accepts connections
published 2026-08-05 · updated 2026-08-05
Why it matters
The port where your vectors actually live — Qdrant's gRPC data plane on :6334 — accepts connections from the internet, and the same host was confirmed to be Qdrant. This was measured by a zero-byte TCP connect, so it proves reachability, not that your data is readable: whether gRPC auth or TLS stands behind the open port was not tested. But an open data plane with no API key configured is full read/write access to every embedding, including stores that may hold agent memory (OWASP ASI06) — treat it as exposed until proven otherwise.
What a probe sees
A zero-byte TCP connect to :6334 (Qdrant gRPC data plane) succeeds from the internet; content was not probed.
Data-plane port — normally internal-only; internet reachability is a misconfiguration. Measured by a zero-byte TCP connect on a host already confirmed by its HTTP API; the hosted scanner never probes data-plane content.
data-plane OWASP ASI06
In the wild
No honeypot telemetry for this service yet (in_the_wild: null in the dataset). We do not invent numbers. The block appears when the honeypot has real data.
Fix it
Fix card: qdrant-dataplane-exposed →
References
- https://qdrant.tech/documentation/guides/security/
- https://qdrant.tech/documentation/guides/configuration/
- https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/
Cite this record
unauth.dev advisory UNAUTH-2026-0009 — published 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0009. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.