top of page
perceptive_background_267k.jpg

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by send…

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 21:03:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Web Technologies

Milvus versions through 2.6.22 and 3.0.0 contain an unauthenticated denial of service vulnerability affecting the management server on port 9091. The unprotected /management/stop endpoint bypasses REST API authentication middleware, allowing remote attackers to send a crafted HTTP GET request with a 'role' parameter to shut down critical service components. Affected components include proxy, datanode, and querynode, whose termination results in denial of service. The vulnerability requires no authentication, making it trivially exploitable by remote attackers. Multiple GitHub issues and pull requests have been filed addressing the flaw, and a VulnCheck advisory has been published. The issue highlights a significant authentication gap in Milvus's management interface design.

Technical details

Mitigation steps:

Affected products:

Milvus 2.6.22
Milvus 3.0.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page