SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-45568

CRITICAL · CVSS 9.1 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The zrok software's Python SDK ProxyShare Flask proxy route is vulnerable to a critical flaw that allows an attacker to manipulate the request path, potentially redirecting requests to a malicious server of their choice. This could lead to unauthorized access to sensitive data or services, posing a significant risk to any organization using versions prior to 2.0.3. Organizations utilizing zrok should prioritize upgrading to version 2.0.3 or later to mitigate this severe security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-45568
Severity
CRITICAL
CVSS
9.1
EPSS
0.36%

Original NVD Description

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target host and causing requests.request to return a server-side response from an attacker-chosen URL. This issue is fixed in version 2.0.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)