CVE-2026-40303Disclosure(netfoundry / zrok)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, count) with no upper bound before any token validation occurs. The function is reached on every request to an OAuth-protected proxy share, allowing an unauthenticated remote attacker to trigger gigabyte-scale heap allocations per request, leading to process-level OOM termination or repeated goroutine panics. Both publicProxy and dynamicProxy are affected. Version 2.0.1 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zrok

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
zrok

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-17: 2Mentions · 2026-04-18: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-18: 104-1704-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-172
Disclosure2
2026-04-181
General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-40303 zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk c… https://www.cve.org/CVERecord?id=CVE-2026-40303

    Post summary

    The post briefly describes a security flaw in zrok’s `GetSessionCookie` function but provides no PoC, exploit, patch, or evidence of active exploitation.

    00010148
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40303 Unauthenticated Denial of Service via Unbounded Heap Allocation in zrok Before 2.0.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40303

    Post summary

    The post releases a new CVE (CVE-2026-40303) describing an unauthenticated Denial of Service caused by an unbounded heap allocation in zrok versions prior to 2.0.1, but provides no additional details on patches, exploits, or active use.

    0001048
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Platform: Ziti Edge Router, Vulnerability Type: Unauthenticated Denial of Service, #CVE-2026-40303 (Critical) https://dailycve.com/platform-ziti-edge-router-vulnerability-type-unauthenticated-denial-of-service-cve-2026-40303-critical/

    Post summary

    An urgent unauthenticated denial‑of‑service vulnerability (CVE‑2026‑40303) affecting Ziti Edge Router has been disclosed, but no PoC, exploit code, active‑exploitation evidence, or patch information is provided.

    0001036
    181 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnetfoundryzrok---

Explore more