github.com/openziti/zrok
govv1.1.11Secure internet sharing made simple.
License Apache-2.0permissive124 versions36 maintainers0 deps4,370 weekly dl
openziti/zrok62
/ 100
Health
update required
github.com/openziti/[email protected] has vulnerabilities — update to latest
Update to >= 2.0.1 to fix known vulnerabilities
- 1 high severity vulnerabilities
Health breakdown0 – 100
20/25
maintenance
6/20
popularity
16/25
security
15/15
maturity
5/15
community
Vulnerabilities
3
1 high2 medium
Advisories (3)
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2026-40304 | zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records | 2.0.1 |
| medium | CVE-2026-40302 | zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering | 2.0.1 |
| high | CVE-2026-40303 | zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing | 2.0.1 |
Health History
Dependency Tree
License Audit
API access
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/github.com/openziti/zrokLast updated · 2026-02-03T16:51:36Z