github.com/milvus-io/milvus
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/milvus-io/milvuspage 1 of 1
- CVE-2025-64513CRITICALCVSS 9.3EG 9.3✓ Fixed in 0.10.3-0.20251107071934-6102f001a9712025-11-10
Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a vulnerability in versions prior to 2.4.24, 2.5.21, and 2.6.5 to bypass all authentication mechanisms in the Milvus Pro…
- CVE-2026-10814HIGHCVSS 7.0EG 7.0✓ Fixed in 0.10.3-0.20260602041816-3d932f1c3e062026-06-04
A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Handler. The manipulation leads to use of w…
- CVE-2026-26190CRITICALCVSS 9.8EG 9.82026-02-13
Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable de…
Check whether github.com/milvus-io/milvus is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/milvus-io/milvus CVEs against the assets you own.
Start Free Scan →