CVE-2026-105048
4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Summary
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zilliz | Attu | 2.6.5 < 3.0.0 | affected |
| Zilliz | Attu | 0 < 2.6.5 | unknown |
Weaknesses
- CWE-1289: CWE-1289 Improper Validation of Unsafe Equivalence in Input
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.