VendorsNetFoundryzrokall versions
Vulnerabilities

NetFoundry zrok

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-45568
zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
Published 2026-07-16 · Analyzed
9.9EPSS 0.005
CVE-2026-42275
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write
Published 2026-05-08 · Analyzed
8.7EPSS 0.005
CVE-2026-45576
zrok copy writes attacker-controlled WebDAV paths outside the destination root
Published 2026-07-16 · Analyzed
8.3EPSS 0.005
CVE-2026-40303
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
Published 2026-04-17 · Analyzed
7.5EPSS 0.006
CVE-2026-40302
zrok has reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
Published 2026-04-17 · Analyzed
6.1EPSS 0.003
CVE-2026-40304
zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records
Published 2026-04-17 · Analyzed
5.3EPSS 0.004