github.com/openziti/zrok/v2
Activity
- Latest release
- 3mo ago
- Total releases
- 11
- Cadence
- ~12 days
- Last 12 months
- 11
Reach
- Stars
- —
Details
- First release
- Dec 19, 2025
| Version | Released | |
|---|---|---|
v2.0.4
patch
|
v2.0.4
patch
Dependencies (61)
+ 53 more |
|
v2.0.3
patch
|
v2.0.3
patch
Dependencies (61)
+ 53 more |
|
v2.0.2
patch
1 CVE
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Fixed in
2.0.3
Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.2
patch
Dependencies (61)
+ 53 more |
|
v2.0.1
patch
2 CVEs
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Fixed in
2.0.3
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.1
patch
Dependencies (61)
+ 53 more |
|
v2.0.0
initial
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Fixed in
2.0.3
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.0
initial
Dependencies (61)
+ 53 more |
|
v2.0.0-rc9
pre
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Fixed in
2.0.3
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.0-rc9
pre
Dependencies (61)
+ 53 more |
|
v2.0.0-rc8
pre
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Fixed in
2.0.3
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.0-rc8
pre
Dependencies (61)
+ 53 more |
|
v2.0.0-rc7
pre
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Fixed in
2.0.3
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.0-rc7
pre
Dependencies (61)
+ 53 more |
|
v2.0.0-rc6
pre
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Fixed in
2.0.3
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.0-rc6
pre
Dependencies (61)
+ 53 more |
|
v2.0.0-rc5
pre
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Fixed in
2.0.3
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.0-rc5
pre
Dependencies (61)
+ 53 more |
|
v2.0.0-rc4
pre
5 CVEs
CVE-2026-40303
GO-2026-5329
GHSA-cpf9-ph2j-ccr9
Jun 25, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45576
GO-2026-5315
GHSA-c656-jcx2-7pqj
Jun 25, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok Fixed in
2.0.3
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42275
GO-2026-5203
GHSA-74m3-9qvm-rp9h
Jun 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok Fixed in
2.0.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40302
GO-2026-5118
GHSA-4fxq-2x3x-6xqx
Jun 25, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40304
GO-2026-5090
GHSA-3jpj-v3xr-5h6g
Jun 25, 2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok Fixed in
2.0.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v2.0.0-rc4
pre
Dependencies (61)
+ 53 more |