zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records
Modified: 6/25/2026
package
pkg:go/github.com/openziti/zrok
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records
Modified: 6/25/2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
Modified: 6/25/2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write
Modified: 6/25/2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root
Modified: 6/25/2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
Modified: 6/25/2026
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records in github.com/openziti/zrok
Modified: 6/25/2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering in github.com/openziti/zrok
Modified: 6/25/2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write in github.com/openziti/zrok
Modified: 6/25/2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root in github.com/openziti/zrok
Modified: 6/25/2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing in github.com/openziti/zrok
Modified: 6/25/2026