github.com/openziti/zrok
Activity
- Latest release
- 7mo ago
- Total releases
- 20
- Cadence
- ~8 days
- Last 12 months
- 6
Reach
- Stars
- —
Details
- First release
- Apr 01, 2025
| Version | Released | |
|---|---|---|
v1.1.11
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.11
patch
Dependencies (61)
+ 53 more |
|
v1.1.9
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.9
patch
Dependencies (66)
+ 58 more |
|
v1.1.10
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.10
patch
Dependencies (66)
+ 58 more |
|
v1.1.8
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.8
patch
Dependencies (66)
+ 58 more |
|
v1.1.7
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.7
patch
Dependencies (66)
+ 58 more |
|
v1.1.6
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.6
patch
Dependencies (66)
+ 58 more |
|
v1.1.5
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.5
patch
Dependencies (66)
+ 58 more |
|
v1.1.4
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.4
patch
Dependencies (66)
+ 58 more |
|
v1.1.3
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (66)
+ 58 more |
|
v1.1.2
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (63)
+ 55 more |
|
v1.1.1
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (63)
+ 55 more |
|
v1.1.0
minor
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (63)
+ 55 more |
|
v1.0.8
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.8
patch
Dependencies (63)
+ 55 more |
|
v1.0.7
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.7
patch
Dependencies (63)
+ 55 more |
|
v1.0.6
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.6
patch
Dependencies (63)
+ 55 more |
|
v1.0.5
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.5
patch
Dependencies (63)
+ 55 more |
|
v1.0.4
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.4
patch
Dependencies (63)
+ 55 more |
|
v1.0.3
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.3
patch
Dependencies (63)
+ 55 more |
|
v1.0.2
patch
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.2
patch
Dependencies (63)
+ 55 more |
|
v1.0.1
initial
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.1
initial
Dependencies (63)
+ 55 more |