CVE-2026-45568
CRITICALzrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
Title source: cnaDescription
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target host and causing requests.request to return a server-side response from an attacker-chosen URL. This issue is fixed in version 2.0.3.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/openziti/zrok/security/advisories/GHSA-jh67-hwqw-m5r7
X_Refsource_Misc x_refsource_misc
https://github.com/openziti/zrok/commit/7c1dc3ecd1c89d8cd2e845a72c3878bd2d31b4fe
X_Refsource_Misc x_refsource_misc
https://github.com/openziti/zrok/releases/tag/v2.0.3
Scores
CVSS v3
9.1
EPSS
0.0036
EPSS Percentile
28.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (2)
netfoundry/zrok
0.4.47 - 2.0.3
openziti/zrok
>= 0.4.47, < 2.0.3
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026