CVE-2026-105048

Summary

The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).

Affected Software

VendorProductVersion RangeStatus
ZillizAttu2.6.5 < 3.0.0affected
ZillizAttu0 < 2.6.5unknown

Weaknesses

  • CWE-1289: CWE-1289 Improper Validation of Unsafe Equivalence in Input

References