CVE-2026-105048: SSRF
Published Oct 2, 2026
·Updated
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).
Affected Software
1 affected component
Zilliz Attu<3.0.0
Event History
Oct 2, 2026
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Zilliz Attu versions before 3.0.0 are affected where the Playground feature is available. The issue allows that feature to proxy requests to private IP addresses.
2
What access does an attacker need?
The provided vector indicates exploitation is network-accessible, requires no privileges, and does not require user interaction. It also indicates high attack complexity.
3
What is the security impact of successful exploitation?
The provided assessment indicates scope can change and integrity impact is low. No confidentiality or availability impact is identified.