Affected by GO-2026-5090
and 3 other vulnerabilities
GO-2026-5090: zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok
GO-2026-5118: zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok
GO-2026-5203: zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok
GO-2026-5329: zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok

The highest tagged major version is
v2.
package
Version:
v0.4.4
Opens a new window with list of versions in this module.
Published: Jul 31, 2023
License: Apache-2.0
Opens a new window with license information.
Imports: 1
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
Source Files
¶
Click to show internal directories.
Click to hide internal directories.