—
GO-2026-5999
milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery in github.com/milvus-io/milvus
Quick fix
GO-2026-5999 — github.com/milvus-io/milvus: upgrade to the fixed version with the command below.
go get github.com/milvus-io/milvus@v0.10.3-0.20260602041816-3d932f1c3e06 Details
milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery in github.com/milvus-io/milvus
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/milvus-io/milvus
Introduced in:
0 Fixed in: 0.10.3-0.20260602041816-3d932f1c3e06 Fix
go get github.com/milvus-io/milvus@v0.10.3-0.20260602041816-3d932f1c3e06 References
- https://github.com/advisories/GHSA-jh6h-v6mp-h22v [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-10814 [ADVISORY]
- https://github.com/milvus-io/milvus/commit/3d932f1c3e065351c4440c27abe1e6479752544d [FIX]
- https://github.com/milvus-io/milvus/pull/50060 [FIX]
- https://github.com/milvus-io/milvus/issues/49857 [REPORT]
- https://vuldb.com/cve/CVE-2026-10814 [WEB]
- https://vuldb.com/submit/831645 [WEB]
- https://vuldb.com/vuln/368262 [WEB]
- https://vuldb.com/vuln/368262/cti [WEB]