Milvus security advisories
3 advisories · 2 critical or high in 12 months · latest Jun 4
3 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 4 | milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery CVE-2026-10814Low4.5fixed in 0.10.3-0.20260602041816-3d932f1c3e06 | Low4.5 | 0.10.3-0.20260602041816-3d932f1c3e06 |
| Feb 11 | Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise CVE-2026-26190Critical9.8fixed in 2.5.27, 2.6.10 | Critical9.8 | 2.5.27, 2.6.10 |
| Nov 132025 | Milvus Proxy has a Critical Authentication Bypass Vulnerability CVE-2025-64513Criticalfixed in 0.10.3-0.20251107071934-6102f001a971, 2.4.24, 2.5.21, 2.6.5 | Critical | 0.10.3-0.20251107071934-6102f001a971, 2.4.24, 2.5.21, 2.6.5 |
About Milvus
The open-source vector database.
Packages watched: github.com/milvus-io/milvus (Go).