Skip to content

Zilliz security advisories

3 advisories across Milvus

Company profile
DateAdvisory
Jun 4milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery
CVE-2026-10814Low4.5fixed in 0.10.3-0.20260602041816-3d932f1c3e06
Feb 11Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
CVE-2026-26190Critical9.8fixed in 2.5.27, 2.6.10
Nov 132025Milvus Proxy has a Critical Authentication Bypass Vulnerability
CVE-2025-64513Criticalfixed in 0.10.3-0.20251107071934-6102f001a971, 2.4.24, 2.5.21, 2.6.5
About Zilliz

Elsewhere on fru.dev: Releases · Repos

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.