CVE-2026-105049 — CVSS 5.8 MEDIUM

Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.

Loading application…