zrok是OpenZiti开源的一个安全的互联网共享工具。 zrok 2.0.1之前版本存在安全漏洞,该漏洞源于对cookie块数量缺少上限检查,可能导致拒绝服务攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40302 | 6.1 MEDIUM | zrok has reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rend |
| CVE-2026-40304 | 5.3 MEDIUM | zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global |
No comments yet