Skip to content

Milvus security advisories

3 advisories · 2 critical or high in 12 months · latest Jun 4

3 advisories

DateAdvisory
Jun 4milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery
CVE-2026-10814Low4.5fixed in 0.10.3-0.20260602041816-3d932f1c3e06
Feb 11Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
CVE-2026-26190Critical9.8fixed in 2.5.27, 2.6.10
Nov 132025Milvus Proxy has a Critical Authentication Bypass Vulnerability
CVE-2025-64513Criticalfixed in 0.10.3-0.20251107071934-6102f001a971, 2.4.24, 2.5.21, 2.6.5
About Milvus

The open-source vector database.

Packages watched: github.com/milvus-io/milvus (Go).

Zilliz elsewhere on fru.dev: Releases · Repos

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.