CVE-2025-64513: Milvus Proxy has Critical Authentication Bypass Vulnerability

Published Nov 10, 2025
·
Updated

Impact What kind of vulnerability is it? Who is impacted? An unauthenticated attacker can exploit this vulnerability to bypass all authentication mechanisms in the Milvus Proxy component, gaining full administrative access to the Milvus cluster. This grants the attacker the ability to read, modify, or delete data, and to perform privileged administrative operations such as database or collection management. All users running affected Milvus versions are strongly advised to upgrade immediately.

Patches Has the problem been patched? What versions should users upgrade to? This issue has been fixed in the following versions: • Milvus 2.4.24 • Milvus 2.5.21 • Milvus 2.6.5

Users should upgrade to these patched versions or later to mitigate the vulnerability.

Workarounds Is there a way for users to fix or remediate the vulnerability without upgrading? If immediate upgrade is not possible, a temporary mitigation can be applied by removing the sourceID header from all incoming requests at the gateway, API gateway, or load balancer level before they reach the Milvus Proxy. This prevents attackers from exploiting the authentication bypass behavior.

References Are there any links users can visit to find out more?

The following pull requests contain the fixes for the affected Milvus branches: • Fix for 2.4 branch • Fix for 2.5 branch • Fix for 2.6 branch

Special thanks to the Volcengine Milvus team at ByteDance(liumingzhe.5689@bytedance.com) for responsibly discovering, reporting, and coordinating the disclosure of this critical authentication bypass vulnerability with the Milvus maintainers.

Other sources

Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a vulnerability in versions prior to 2.4.24, 2.5.21, and 2.6.5 to bypass all authentication mechanisms in the Milvus Proxy component, gaining full administrative access to the Milvus cluster. This grants the attacker the ability to read, modify, or delete data, and to perform privileged administrative operations such as database or collection management. This issue has been fixed in Milvus 2.4.24, 2.5.21, and 2.6.5. If immediate upgrade is not possible, a temporary mitigation can be applied by removing the sourceID header from all incoming requests at the gateway, API gateway, or load balancer level before they reach the Milvus Proxy. This prevents attackers from exploiting the authentication bypass behavior.

NVD

Affected Software

5 affected componentsFixes available
Milvus Milvus Proxy<2.4.24, <2.5.21, <2.6.5
go/github.com/milvus-io/milvus<0.10.3-0.20251107071934-6102f001a971
0.10.3-0.20251107071934-6102f001a971
go/github.com/milvus-io/milvus>=2.6.0<2.6.5
2.6.5
go/github.com/milvus-io/milvus>=2.5.0<2.5.21
2.5.21
go/github.com/milvus-io/milvus>=0.10.4<2.4.24
2.4.24

Event History

Nov 10, 2025
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Nov 13, 2025
Advisory Published
via GitHub·03:55 PM
Data Sourced
via GitHub·03:55 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-64513?

CVE-2025-64513 is a critical vulnerability due to its potential for unauthenticated access to Milvus Proxy, allowing full administrative control.

2

How do I fix CVE-2025-64513?

To mitigate CVE-2025-64513, update Milvus Proxy to version 2.4.24, 2.5.21, or 2.6.5 or later.

3

What impacts does CVE-2025-64513 have on Milvus Proxy?

CVE-2025-64513 allows unauthenticated attackers to bypass all authentication mechanisms in Milvus Proxy.

4

Which versions of Milvus Proxy are affected by CVE-2025-64513?

CVE-2025-64513 affects Milvus Proxy versions prior to 2.4.24, 2.5.21, and 2.6.5.

5

Is an authenticated user safe from CVE-2025-64513?

An authenticated user is not safe from CVE-2025-64513, as the vulnerability allows an unauthenticated attacker to gain administrative access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203