
🚨 Critical - zrok Python SDK SSRF Vulnerability (CVE-2026-45568) The zrok Python SDK ProxyShare feature is vulnerable to SSRF due to unsafe handling of absolute URL paths via urljoin(). An attacker can supply a crafted path to redirect server-side requests to arbitrary internal or external hosts. Successful exploitation may expose internal services, metadata endpoints, and sensitive network resources. 👉 Affected: zrok >=0.4.47 <=1.1.11. Administrators should restrict exposure of ProxyShare endpoints and monitor vendor advisories for updates.
Post summary
The tweet announces a critical SSRF vulnerability (CVE‑2026‑45568) in the zrok Python SDK, detailing the flaw and advising limited exposure of ProxyShare endpoints while awaiting vendor updates.
