← advisory ledger

ADVISORY UNAUTH-2026-0020
TYPE exposure-class
PRODUCT Weaviate
SEVERITY HIGH

HIGH

Weaviate gRPC data plane (:50051) accepts connections

published 2026-08-05 · updated 2026-08-05

Why it matters

The port where your vectors actually live — Weaviate's gRPC data plane on :50051 — accepts connections from the internet, and the same host was confirmed to be Weaviate. This was measured by a zero-byte TCP connect, so it proves reachability, not that your data is readable: whether gRPC auth or TLS stands behind the open port was not tested. But Weaviate is wide open unless you turned on authentication, so an open :50051 usually means every vector readable and writable, including stores that may hold agent memory (OWASP ASI06) — treat it as exposed until proven otherwise.

What a probe sees

A zero-byte TCP connect to :50051 (Weaviate gRPC data plane) succeeds from the internet; content was not probed.

Data-plane port — normally internal-only; internet reachability is a misconfiguration. Measured by a zero-byte TCP connect on a host already confirmed by its HTTP API; the hosted scanner never probes data-plane content.

data-plane OWASP ASI06

In the wild

No honeypot telemetry for this service yet (in_the_wild: null in the dataset). We do not invent numbers. The block appears when the honeypot has real data.

Fix it

Fix card: weaviate-dataplane-exposed →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0020 — published 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0020. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.