CVE-2026-69111
- EPSS 0.57%
- Veröffentlicht 05.08.2026 19:18:23
- Zuletzt bearbeitet 06.08.2026 15:17:25
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploi...
- EPSS 0.09%
- Veröffentlicht 04.06.2026 15:00:19
- Zuletzt bearbeitet 22.07.2026 20:10:00
A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Handler. The manipulation leads to use of weak hash. T...
CVE-2026-26190
- EPSS 36.91%
- Veröffentlicht 13.02.2026 18:44:33
- Zuletzt bearbeitet 18.02.2026 19:11:12
Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authe...