Deserialization Vulnerability in Milvus HTTP Endpoint
CVE-2025-15453
Key Information:
Badges
What is CVE-2025-15453?
A critical deserialization vulnerability has been identified in the Milvus product affecting versions up to 2.6.7. This issue arises from improper handling of the argument code within the function expr.Exec of the HTTP Endpoint component located in pkg/util/expr/expr.go. Attackers can potentially exploit this vulnerability remotely, leading to unauthorized actions or access. A fix is scheduled for the upcoming release, version 2.6.8, aimed at mitigating this security risk.
Affected Version(s)
milvus 2.6.0
milvus 2.6.1
milvus 2.6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
