HIGH8.7CVE-2026-42275zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok from 0, <= 1.1.11
HIGH8.7CVE-2026-42275zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok from 0
HIGH7.5CVE-2026-40303zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok from 0, <= 1.1.11
HIGH7.5zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok
from 0
MEDIUM6.1zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok
from 0, <= 1.1.11
MEDIUM6.1zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok
from 0
MEDIUM5.3zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok
from 0, <= 1.1.11
MEDIUM5.3zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok
from 0
—zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok
>= 0.4.23, <= 1.1.11
—zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok
>= 0.4.23