References https://github.com/milvus-io/milvus/security/advisories/GHSA-mhjq-8c7m-3f7p https://www.secrss.com/articles/84926 https://avd.aliyun.com/detail?id=AVD-2025-64513 https://nvd.nist.gov/vuln/detail/CVE-2025-64513 https://cloud.tencent.com/developer/article/2629585 https://www.sentinelone.com/vulnerability-database/cve-2025-64513/ https://cn-sec.com/archives/4676463.html https://securityonline.info/critical-authentication-bypass-vulnerability-found-in-milvus-proxy-cve-2025-64513-cvss-9-3/ https://cyberpress.org/milvus-proxy-vulnerability/ https://github.com/shinyseam/CVE-2025-64513
Related VulnerabilitiesPoCCVE-2026-23693: ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp ProxyPoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassPoCCVE-2025-26399: SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCELobeChat /webapi/proxy 服务器端请求伪造漏洞(CVE-2026-54157)东胜物流软件 /PriceCarrier/CrmProxyMailListHtmlGridSource.aspx SQL 注入漏洞关于用友GRP-U8Cloud产品getBudgetReleaseProjectList及U8AppProxy及fbpm-modeler存在命令执行漏洞的安全通告Apache Druid /proxy/coordinator@ 服务器端请求伪造漏洞(CVE-2025-27888)PoCCVE-2026-26190: Milvus - Unauthenticated Metrics API AccessMilvus 未授权访问漏洞(CVE-2026-26190)Milvus存在代码执行漏洞(CVE-2026-26190)Gradio /proxy 服务器端请求伪造漏洞(CVE-2023-34239)PoCCVE-2025-62168: Squid Proxy - HTTP Authentication Credentials DisclosurePoClitellm-unauth-model-exposure: LiteLLM Proxy - Model Exposure