Should I use Milvus?
Open-source vector database built for scale - milvus.io
Depends. Buy it if you run AI similarity search at serious scale and have infra staff to operate a distributed database. Skip it for small apps or prototypes — pgvector or a lightweight hosted vector DB does that job with far less pain.
Confidence
Medium. Based on ~20 public sources. Lens-review results for 'Zeiss Milvus' cameras and an unrelated ITSM 'Milvus' were excluded.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support qualityNo support evidence in sources reviewed
- Security posture
Pricing
Free (self-hosted)
Milvus Open Source
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Zilliz CloudPay-as-you-go
Best for
- →RAG and AI search teams at scale
- →Billion-scale similarity search
- →Engineering orgs wanting open source
- →Teams with dedicated DevOps capacity
Not for
- ×Hobby projects or apps under ~1M vectors
- ×Teams with no DevOps or Kubernetes experience
- ×Buyers wanting zero-maintenance managed simplicity
- ×Anyone who can't patch promptly after CVEs
Gotchas - check before you buy
high
CVE-2025-64513: unauthenticated auth bypass in the proxy. Patch immediately if internet-exposed.
high
Unauthenticated denial-of-service via management stop affects 2.6.22 and 3.0.0.
medium
Free software, not free to run: infra bills dominate; vendor claims up to 80% optimizable.
medium
Managed path is Zilliz Cloud pay-as-you-go; costs vary with usage at scale.
Pros and cons
Pros
- +Called the fastest open-source vector database by user benchmarks
- +Handles billion-scale image search in documented production cases
- +Open source and free to self-host
- +Won Reddit's bake-off over Qdrant for production ANN search
- +Large community with 35K+ GitHub stars
Cons
- −Distributed system; steep learning curve for vector DB newcomers
- −Authentication bypass CVE disclosed November 2025
- −Self-hosting costs real money despite 'free' label
- −Recurring vulnerabilities across versions demand constant patching discipline
Sources & method
Analyzed 9/20/2026 - 10 sources - Active CVE history through 2025–2026; safe with fast patching.
official x4review x3security x2news x1
- Unauthenticated authentication bypass in Milvus Proxy (CVE-2025-64513), Disclosed Nov 10, 2025; an unauthenticated attacker could bypass auth. Fix shipped in Milvus 2.5.27 line.
- Unauthenticated denial of service via management stop, Affects Milvus 2.6.22 and 3.0.0, per VulnCheck advisory (Apr 2026).
- CVE-2026-26190, Milvus listed in Aqua Security's vulnerability database (Feb 2026); details thin in reviewed sources.
- Vulnerabilities in official Docker image, GitHub issue flags high/medium/low vulnerabilities in the official Milvus v2.5.8 image.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.