CVE-2026-105048

Published: Ott 03, 2026 Last Modified: Ott 03, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,0
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).

1289

Improper Validation of Unsafe Equivalence in Input

Incomplete
Common Consequences
Security Scopes Affected:
Other
Potential Impacts:
Varies By Context
Applicable Platforms
All platforms may be affected
View CWE Details
https://bishopfox.com/blog/zilliz-attu-2-6-5
https://github.com/zilliztech/attu/issues/1028