VDB
Sign up
—

GO-2025-4114

Milvus Proxy has a Critical Authentication Bypass Vulnerability in github.com/milvus-io/milvus

Quick fix

GO-2025-4114 — github.com/milvus-io/milvus: upgrade to the fixed version with the command below.

go get github.com/milvus-io/milvus@v0.10.3-0.20251107071934-6102f001a971

Details

Milvus Proxy has a Critical Authentication Bypass Vulnerability in github.com/milvus-io/milvus.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/milvus-io/milvus before v2.4.24, from v2.5.0 before v2.5.21, from v2.6.0 before v2.6.5.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/milvus-io/milvus
Introduced in: 0Fixed in: 0.10.3-0.20251107071934-6102f001a971
Fixgo get github.com/milvus-io/milvus@v0.10.3-0.20251107071934-6102f001a971

References