CVE-2026-45568
zrok is a tool for sharing web services, files, and network resources. A flaw in versions before 2.0.3 allows an attacker to supply an absolute URL that the proxy route will use to fetch data from that URL, potentially exposing internal resources. The issue is fixed in zrok 2.0.3.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
zrok software, versions prior to 2.0.3, used by developers and teams sharing web services and files.
Real-world impact
An attacker could trick the zrok proxy into fetching data from an arbitrary URL, exposing internal network resources or retrieving sensitive data from the server.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability is exploitable over the network with no authentication, and it allows an attacker to read or manipulate data on the server, giving high confidentiality and integrity impact.
What to do about it
- 01Upgrade zrok to version 2.0.3 or later.
- 02Restart the zrok service if necessary.
NVD description indicates fix in version 2.0.3
Timeline
- Jul 16, 2026 · 17d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 20, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/openziti/zrok/commit/7c1dc3…patch
- github.com/openziti/zrok/releases/tag/…release notes
- github.com/openziti/zrok/security/advi…vendor advisory