CVE-2025-64513Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a vulnerability in versions prior to 2.4.24, 2.5.21, and 2.6.5 to bypass all authentication mechanisms in the Milvus Proxy component, gaining full administrative access to the Milvus cluster. This grants the attacker the ability to read, modify, or delete data, and to perform privileged administrative operations such as database or collection management. This issue has been fixed in Milvus 2.4.24, 2.5.21, and 2.6.5. If immediate upgrade is not possible, a temporary mitigation can be applied by removing the sourceID header from all incoming requests at the gateway, API gateway, or load balancer level before they reach the Milvus Proxy. This prevents attackers from exploiting the authentication bypass behavior.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-20: 102-20
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Patch

    `Milvus` Proxy affected by critical authentication bypass (CVE-2025-64513). Update to mitigate unauthorized access. #Milvus #AuthBypass #InfoSec https://www.pulsepatch.io/posts/cve-2025-64513-milvus-proxy-authentication-bypass

    Post summary

    Milvus Proxy suffers a critical authentication bypass (CVE-2025-64513) and an update is available to mitigate unauthorized access.

    0000043
    1 followersView on X

Explore more