PatchSiren

milvus-io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH milvus-io CVE published 2026-08-05

CVE-2026-69111

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. The /management/stop endpoint is unprotected and can be exploited by supplying a 'role' parameter to shut down the proxy, datanode, or querynode components, resulting in denial o [truncated]

LOW milvus-io CVE published 2026-06-04

CVE-2026-10814

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Handler. The manipulation leads to use of weak hash. The attack needs to be performed locally. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been dis [truncated]