PT-2026-41957 · Zrok · Zrok

CVE-2026-45568

·

Published

2026-05-19

·

Updated

2026-07-20

CVSS v4.0

9.9

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions zrok versions 0.4.47 through 1.1.11
Description The ProxyShare feature in the Python SDK is susceptible to Server-Side Request Forgery (SSRF), a flaw where a server is tricked into making requests to an unintended destination. This occurs because the proxy() function uses urljoin() to handle absolute URL paths unsafely. An attacker can provide a crafted path that replaces the configured target host with an arbitrary internal or external host, potentially exposing internal services, metadata endpoints, and sensitive network resources.
Recommendations Restrict exposure of ProxyShare endpoints. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45568
GHSA-JH67-HWQW-M5R7
PYSEC-2026-577

Affected Products

Zrok