CVE-2026-105048: Zilliz Attu

Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.

The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).

Affected products

  • Zilliz Attu: from 2.6.5, before 3.0.0 (fixed in 3.0.0)

Published 2026-10-02. Last modified 2026-10-06.