Chroma Review 2026: Great for Prototypes, One Unpatched CVE You Need to Know
Chroma is still the fastest way to get a RAG prototype running -- four functions, no infrastructure, works inside your Python process. That reputation is earned and it hasn't changed. What has changed since most people last looked: Chroma now runs a genuinely commercial hosted product, Chroma Cloud, with $250/month Team plans, SOC 2 Type II, and enterprise BYOC deployment -- built by a company that has disclosed no funding beyond its original 2023 seed round. And as of this review, a maximum-severity, unauthenticated remote-code-execution vulnerability publicly disclosed in May 2026 remains unpatched in the current shipping version. This review covers what actually works, what actually costs money, and what you need to know before you expose a Chroma server to anything you don't fully trust.
| OSS license | Apache 2.0, still free |
| Live GitHub stars | 29,355 |
| Chroma Cloud entry | $0/mo + usage |
| Cheapest paid tier | Team, $250/mo + usage |
| Disclosed funding | $18M seed only (April 2023) |
| Open critical CVE | CVE-2026-45829, unpatched |
Chroma still wins the first hour. Whether it wins the first year depends on a question most people haven't asked yet: is it patched?
"Chroma earned its reputation honestly. `pip install chromadb`, four functions, and you have a working vector store embedded in your own process before you've finished your coffee. That part of the pitch is still completely true in 2026. What's changed is what happens next: Chroma now wants you to graduate to Chroma Cloud, a real commercial product with real enterprise pricing, run by a company that -- as far as public records show -- has raised exactly one funding round since 2023. And right now, sitting in the current shipping release, is a maximum-severity vulnerability that lets an unauthenticated attacker run code on your server. Nobody's patched it yet. That's not a footnote; that's the first thing you should know before this review tells you anything else."
None of this means don't use Chroma. It means use it with your eyes open about which Chroma you're using: the disposable local prototype (still great), the self-hosted server exposed to a network you don't fully control (currently risky, fixable with configuration), or Chroma Cloud (a real managed product, priced like one, from a company that hasn't yet shown the funding trail you'd expect from something this commercial).
One tiny embedded library, one hosted distributed rewrite, same four-function API either way.
Chroma is an open-source, Apache-2.0 licensed embedding database for AI applications: it stores documents, their vector embeddings, and metadata, and lets you query by similarity, keyword, or both. The core API really is four functions -- create_collection, add, query, get -- and it runs three ways: fully in-memory inside your Python process, persisted to a local directory, or as a standalone client/server you point multiple apps at. Chroma Cloud is the newer, hosted layer: the same client API, but backed by "Chroma Distributed" -- a Rust rewrite that runs on AWS/GCP object storage instead of a single machine, so it can scale past what self-hosted single-node Chroma can handle.
The one-sentence version: if you're prototyping or running something small on one machine, self-hosted Chroma is still free and still fast to start. If you need it to survive real traffic without an on-call rotation, Chroma Cloud is the company's actual answer -- and it is priced like a serious product, not a side project.
Real developer traction, a genuinely commercial cloud product -- and a funding history that hasn't kept pace with either.
chroma-core/chroma, verified on GitHub, Sep 22, 2026.
Company-stated, Sep 2026.
Company-stated member count, not active-user count.
Single seed round, April 2023 -- no later round found.
| Date | Event | Result |
|---|---|---|
| Oct 22, 2022 | Initial open-source release | chroma-core/chroma published on GitHub |
| Apr 2023 | $18M seed round, led by Astasia Myers (Quiet Capital) | $75M post-money valuation; angels included Naval Ravikant, Guillermo Rauch |
| 2024 | Chroma Cloud private preview begins | Early access to the hosted distributed rewrite |
| Aug 18, 2025 | Chroma Cloud reaches general availability | Usage-based pricing, no minimums, Team/Enterprise tiers launch |
| 2026-09-22 (checked) | No Series A or later round found on Crunchbase/Tracxn/PitchBook | Still running on the original $18M as far as public records show |
One dramatic hosted-migration win. A recurring, well-documented memory-leak pattern on the self-hosted side.
"Migrating to Chroma removed the pain. No one's getting woken up on call anymore." Before: 10-minute outages every 4-5 hours, daily 10-second latency spikes. After: P50 20ms / P90 70ms / P99 consistently under 100ms across tens of thousands of customer collections.
A service running 2,233 self-hosted collections upgraded to Chroma 0.5.x and began OOM-crashing nightly within 3 days -- the segment cache has no default eviction policy. Fixed only by manually setting CHROMA_SEGMENT_CACHE_POLICY=LRU."When concurrency increases...performance can drop sharply." Their own benchmark found pgvector held more consistent latency than Chroma under high-concurrency load. Their production verdict: Chroma suits prototyping; move to a more mature solution for production.
A genuine free tier, then a real per-unit usage meter, then a $250/month floor once you want SOC 2.
Starter
10 databases, 10 team members, $5 free credit.
- Community Slack access
- Full usage-metered API access
Team
100 databases, 30 team members, $100 included usage credit (non-rollover).
- Slack support, SOC 2 Type II
- Volume-based usage discounts
Enterprise
Unlimited databases and members.
- Single-tenant clusters, BYOC
- Dedicated support, SLAs
Your answer depends on how far you are past "does this idea even work."
Self-hosted Chroma, in-memory or PersistentClient, is still the fastest option available.
Stop and read the Security section first -- enable authentication before anything else.
Chroma Cloud Starter ($0 + usage) is enough to test the migration path.
Team ($250/mo + usage) or Enterprise, depending on compliance needs.
Dense vectors alone were never the whole story. Chroma finally ships the other half natively.
Until recently, combining Chroma's semantic (dense-vector) search with keyword-style search meant bolting on a separate system yourself. Chroma now ships first-class sparse vector search -- BM25 and SPLADE -- alongside dense vectors, merged through Reciprocal Rank Fusion (RRF) into a single hybrid ranking. BM25 handles classic keyword relevance (term frequency and rarity); SPLADE expands a query or document with model-inferred related terms, so it catches meaning a pure keyword match would miss. This directly contradicts a few stale comparison articles still circulating that describe Chroma as lacking hybrid search -- as of this feature's launch, it doesn't.
Official Chroma video: Lexical Search in Chroma — Full Text Search, BM25 & SPLADE.
Published by the official "Chroma" YouTube channel (youtube.com/@trychroma). Published Apr 2, 2026.
- Hybrid search (dense + BM25/SPLADE via RRF) is a real, first-class API now, not a workaround you build yourself.
- The core 4-function API stays identical whether you're in-memory, self-hosted, or on Chroma Cloud -- migrating up doesn't mean rewriting your app.
- Fastest realistic path from zero to a working RAG demo of any option in this category.
- Sparse-vector search setup (schema configuration) is new enough that community tutorials and Stack Overflow coverage are still thin -- expect to read the docs directly.
- Hybrid ranking quality still depends heavily on which embedding model and SPLADE checkpoint you pair it with; Chroma doesn't pick this for you.
Create a collection, add your data, query it back -- the same four steps whether you're local or in the cloud.
The hosted version isn't just "Chroma on someone else's server" -- it's a genuine distributed rewrite.
Chroma Cloud runs on Chroma Distributed, a from-scratch Rust implementation built after the team learned the limits of the single-node engine. It uses SPANN combined with SPFresh for the vector index (so it can scale horizontally instead of holding everything in one process's memory) and wal3, an object-storage-backed write-ahead log, to keep writes durable and consistent across AWS and GCP. For enterprises that need data to stay inside their own cloud account, BYOC (Bring Your Own Cloud) deploys the same distributed system inside the customer's own VPC, with multi-region replication and point-in-time recovery.
Chroma ships its own MCP server, with a docs page written specifically for Claude Desktop.
Chroma maintains an official Model Context Protocol server, chroma-core/chroma-mcp (597 GitHub stars), exposing collection management, document add/update/delete, vector + keyword search, and metadata filtering as callable MCP tools. Chroma's own documentation includes a page built specifically for wiring this into Claude Desktop: add a JSON block under Settings → Developer → Edit Config, restart, and a hammer icon appears in the chat box exposing Chroma's tools directly to Claude. The documented use cases are concrete -- a shared team knowledge base Claude can query, and "project memory" where Claude is instructed to proactively check Chroma when memory-related topics come up in conversation.
You're paying for writes, storage, and reads separately -- and writes are the expensive one.
| Usage meter | Rate | What it means in practice |
|---|---|---|
| Write | $2.50 / logical GiB | Charged once per add/update/upsert -- background compaction and reindexing are free. |
| Storage | $0.33 / GiB-month | Billed in GiB-hours, so short-lived test collections cost proportionally little. |
| Query | $0.0075 / TiB queried + $0.09 / GiB returned | Two-part: scanning the index is cheap, egressing large result payloads is the real lever. |
| Fork | $0.03 / request | Copy-on-write collection forking -- useful for cheap dev/staging copies of a prod collection. |
| Sync ingestion | $0.04 / GiB processed | For Chroma's managed data-ingestion/sync pipelines, separate from manual writes. |
This is the section to read before you deploy anything. A maximum-severity RCE is currently unpatched.
POST /api/v2/tenants/{tenant}/databases/{db}/collections processes an embedding-function configuration -- including a Hugging Face model reference with trust_remote_code: true -- before checking authentication. An unauthenticated attacker can force the server to download and execute a malicious model, gaining full process compromise: environment variables, API keys, mounted secrets, and all stored data. Affects chromadb (PyPI) 1.0.0 through the current latest release, 1.5.9. Researcher HiddenLayer reported it privately on Feb 17, 2026, followed up three more times through Apr 16, then disclosed publicly on May 18, 2026 after receiving no vendor response. We checked the 1.5.9 changelog directly and confirmed it contains no security fix, and confirmed via PyPI that 1.5.9 is still the latest published release as of this review.On the Chroma Cloud side, the company's own security page claims a completed SOC 2 Type II examination, plus encryption in transit/at rest, MFA, RBAC, AWS multi-AZ hosting, and annual penetration testing -- but it makes no HIPAA or GDPR certification claim, and does not mention this CVE at all. Whether Chroma Cloud's own infrastructure is exposed to the same endpoint is not disclosed either way in that page; treat the self-hosted mitigation guidance above as mandatory regardless of which deployment you run.
The right fit depends on how much you trust your own network perimeter.
| Situation | Why Chroma fits (or doesn't) | Likely path |
|---|---|---|
| Solo dev or hackathon, prototyping a RAG idea | Fastest zero-to-working-demo option in the category | Self-hosted, in-memory, free |
| Small team, single machine, low traffic, network-isolated | Free, simple, hybrid search now built in | Self-hosted PersistentClient, with auth enabled |
| Growing product, outgrowing one machine | Same API, no rewrite, serverless scaling | Chroma Cloud Starter or Team |
| Regulated industry, needs SOC 2 / data residency | Team plan (SOC 2) or Enterprise BYOC | Team or Enterprise |
| Any self-hosted deployment reachable by an untrusted network | CVE-2026-45829 is currently unpatched — this is a hard blocker until fixed or fully mitigated | Enable auth immediately or don't expose the port |
Four real gaps, not manufactured ones.
CVE-2026-45829 has been public since May 2026. No patched release has shipped since. For a project this widely embedded in other people's AI stacks, that response time is a real trust problem, not a minor bug.
Open GitHub issues (#5843, #3296, #4024, #1908) and one detailed independent production post-mortem all describe the same shape of problem: unbounded memory growth under multi-collection, sustained load.
Chroma Cloud is priced and positioned like a well-funded enterprise product (SOC 2, BYOC, dedicated support). Public funding records don't show the capital trail you'd expect behind that -- worth a diligence question before a long-term commercial commitment.
Independent benchmarking (AltexSoft) found pgvector more consistent than Chroma under high concurrency; multiple sources agree Chroma's sweet spot is well under the scale where Qdrant or Milvus start to shine.
Chroma's real competitive set splits by what you actually need next.
| If you mostly need... | Compare Chroma with... |
|---|---|
| Best self-hosted price-performance and lowest filtered-query latency at scale | Qdrant (qdrant.tech) — 34,754 GitHub stars, Rust, better-funded, read JAVIS's Qdrant review |
| The most mature native hybrid search and a vectorizer-module ecosystem | Weaviate (weaviate.io) — 16,837 GitHub stars |
| Zero self-hosting at all, fully managed SaaS, willing to pay a $50/mo floor | Pinecone (pinecone.io) — closed-source, serverless-only |
| Proven massive distributed scale from day one | Milvus (milvus.io) — 46,217 GitHub stars, the most-starred option in the category |
| You already run Postgres and don't want a new database at all | pgvector (github.com/pgvector/pgvector) — 23,121 GitHub stars, an extension not a standalone DB |
I have not verified a standard public affiliate program for Chroma.
At the time of this review, Chroma does not appear to run a public creator/affiliate referral program. Every CTA in this article points to Chroma's official site, unmodified — no tracking parameters, no invented commission link. The unpatched CVE discussed in this review would be disclosed identically whether or not any affiliate relationship existed.
Go to the official product — but read the Security section first.
Open ChromaRead the comparison that matches your real question.
Choose the next articleChroma sits inside the same vector-database category as two other JAVIS reviews.
Questions people are actually searching right now
Is Chroma free?
The core library (chromadb) is free and Apache-2.0 licensed, self-hosted or embedded. Chroma Cloud has a free Starter tier ($0/mo + usage, with $5 in signup credit) and paid Team ($250/mo + usage) and Enterprise tiers.
Is ChromaDB safe to use in production right now?
Self-hosted ChromaDB has a currently unpatched, maximum-severity vulnerability (CVE-2026-45829, CVSS 9.3) that allows unauthenticated remote code execution. Chroma also ships with authentication disabled by default. If you self-host, enable authentication immediately and never expose the API to an untrusted network until a patch ships.
What is CVE-2026-45829?
A pre-authentication code-injection flaw in ChromaDB's collections-creation endpoint: an attacker can force the server to load and execute a malicious Hugging Face model before any auth check runs, gaining full server compromise. Publicly disclosed May 18, 2026 by researcher HiddenLayer after no vendor response; still unpatched in the current release (1.5.9) as of this review.
What is Chroma Cloud and when did it launch?
Chroma Cloud is Chroma's hosted, serverless product, built on a distributed Rust rewrite called Chroma Distributed. It entered private preview in 2024 and reached general availability on August 18, 2025.
Does Chroma support hybrid search?
Yes, as of Chroma's sparse-vector-search launch: dense vector similarity plus BM25 and SPLADE sparse search, merged via Reciprocal Rank Fusion. Older comparison articles claiming Chroma lacks hybrid search are out of date.
How much funding has Chroma raised?
Publicly, one round: an $18M seed in April 2023 at a $75M valuation, led by Astasia Myers of Quiet Capital. No Series A or later round appears on Crunchbase, Tracxn, or PitchBook as of this review's check (Sep 22, 2026).
Chroma vs Pinecone vs Weaviate vs Qdrant — which should I pick?
Chroma wins for the fastest local prototype. Pinecone wins for zero-infrastructure managed SaaS. Weaviate wins for the most mature native hybrid search. Qdrant wins for self-hosted price-performance and low-latency filtered queries at real scale. See the Alternatives section for the full breakdown.
Does Chroma support MCP for use with Claude?
Yes. Chroma maintains an official MCP server (chroma-core/chroma-mcp) and a documentation page specifically for connecting it to Claude Desktop, exposing search, document management, and collection tools directly inside a Claude conversation.
Where this came from, and when it was checked.
GitHub stats (stars/forks/license/description): GitHub data for github.com/chroma-core/chroma, Sep 22, 2026.
Funding history: trychroma.com/company/seed (official, first-party), cross-checked live against Crunchbase, Tracxn, and PitchBook search results, Sep 22, 2026 -- no round beyond the April 2023 seed was found on any of them.
Pricing (Starter/Team/Enterprise, usage rates): trychroma.com/pricing and docs.trychroma.com/cloud/pricing, both official, read directly, Sep 22, 2026.
Chroma Cloud architecture and GA date: trychroma.com/changelog/introducing-chroma-cloud and trychroma.com/engineering/distributed-chroma-byoc, both official.
CVE-2026-45829: GitHub Security Advisory GHSA-f4j7-r4q5-qw2c (CVSS 9.3, affected versions 1.0.0-1.5.9, no patch available as of last update 2026-05-29); HiddenLayer's own disclosure post (exact timeline and technical root cause); BleepingComputer (secondary corroboration and mitigation guidance); cross-checked live against the chromadb PyPI package (latest version still 1.5.9 on 2026-09-22) and the 1.5.9 GitHub release changelog (no security fix mentioned).
Default-no-auth confirmation: docs.trychroma.com/deployment/docker, official.
Hybrid/sparse search: trychroma.com/project/sparse-vector-search and docs.trychroma.com/cloud/schema/sparse-vector-search, both official.
MCP support: github.com/chroma-core/chroma-mcp (official repo, 597 stars) and docs.trychroma.com/integrations/frameworks/anthropic-mcp (official Claude-specific setup docs).
Customer case study: trychroma.com/customers/mintlify-case-study, official, attributed to Nick Khami (Mintlify).
Real screenshots/media: trychroma.com official card image, opengraph.githubassets.com repo card, and the official Chroma BYOC engineering-blog image.
Official video: youtube.com/watch?v=XHEgXDff2xw, authorship confirmed on YouTube (author "Chroma", @trychroma), published Apr 2, 2026.
User sentiment: GitHub Issues on the official repo (#5843, #3296, #4024, #1908) for a first-party-documented recurring pattern; DEV Community and AltexSoft for independent, named, sourced sentiment. G2's review pages could not be read directly and were used only as an aggregate-score citation, not for quote-mining.
