—
GO-2026-5999
milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery in github.com/milvus-io/milvus
Quick fix
GO-2026-5999 — github.com/milvus-io/milvus: upgrade to the fixed version with the command below.
go get github.com/milvus-io/milvus@v0.10.3-0.20260602041816-3d932f1c3e06Details
milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery in github.com/milvus-io/milvus
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/milvus-io/milvus
Introduced in:
0Fixed in: 0.10.3-0.20260602041816-3d932f1c3e06Fix
go get github.com/milvus-io/milvus@v0.10.3-0.20260602041816-3d932f1c3e06References
- https://github.com/advisories/GHSA-jh6h-v6mp-h22v[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-10814[ADVISORY]
- https://github.com/milvus-io/milvus/commit/3d932f1c3e065351c4440c27abe1e6479752544d[FIX]
- https://github.com/milvus-io/milvus/pull/50060[FIX]
- https://github.com/milvus-io/milvus/issues/49857[REPORT]
- https://vuldb.com/cve/CVE-2026-10814[WEB]
- https://vuldb.com/submit/831645[WEB]
- https://vuldb.com/vuln/368262[WEB]
- https://vuldb.com/vuln/368262/cti[WEB]