PT-2026-41957 · Zrok · Zrok
CVE-2026-45568
·
Published
2026-05-19
·
Updated
2026-07-20
CVSS v4.0
9.9
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
zrok versions 0.4.47 through 1.1.11
Description
The ProxyShare feature in the Python SDK is susceptible to Server-Side Request Forgery (SSRF), a flaw where a server is tricked into making requests to an unintended destination. This occurs because the
proxy() function uses urljoin() to handle absolute URL paths unsafely. An attacker can provide a crafted path that replaces the configured target host with an arbitrary internal or external host, potentially exposing internal services, metadata endpoints, and sensitive network resources.Recommendations
Restrict exposure of ProxyShare endpoints.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zrok