SCA: security update for github.com/milvus-io/milvus (GHSA-mhjq-8c7m-3f7p)

critical Tenable Cloud Security Plugin ID 436036

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker
can exploit a vulnerability in versions prior to 2.4.24, 2.5.21, and 2.6.5 to bypass all authentication
mechanisms in the Milvus Proxy component, gaining full administrative access to the Milvus cluster. This
grants the attacker the ability to read, modify, or delete data, and to perform privileged administrative
operations such as database or collection management. This issue has been fixed in Milvus 2.4.24, 2.5.21,
and 2.6.5. If immediate upgrade is not possible, a temporary mitigation can be applied by removing the
sourceID header from all incoming requests at the gateway, API gateway, or load balancer level before they
reach the Milvus Proxy. This prevents attackers from exploiting the authentication bypass behavior.
(CVE-2025-64513)

See Also

https://github.com/advisories/GHSA-mhjq-8c7m-3f7p

Plugin Details

Severity: Critical

ID: 436036

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 11/13/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.48

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2025-64513

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/13/2025

Vulnerability Publication Date: 11/10/2025

Reference Information

CVE: CVE-2025-64513

cwe: CWE-287