CVE-2026-40303 is a denial-of-service vulnerability in zrok versions prior to 2.0.1 that affects the endpoints.GetSessionCookie function. The flaw allows unauthenticated remote attackers to trigger unbounded heap memory allocation by manipulating cookie chunk count values, impacting both publicProxy and dynamicProxy deployments. This vulnerability is reachable on every OAuth-protected proxy share request, making it trivial to exploit. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no privileges or user interaction. An attacker can trigger gigabyte-scale heap allocations per request without authentication, leading to process-level out-of-memory termination or repeated goroutine panics that effectively disable the service. The impact is strictly availability-focused, with no confidentiality or integrity compromise. Exploitation status indicates this vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and is inactive on security hot lists. The EPSS score of 0.000290000 reflects minimal observed exploitation activity in the wild. Users should prioritize upgrading to zrok version 2.0.1 or later, though the low exploitation prevalence suggests this may represent a proactive disclosure rather than active threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.1CPE matchmatch criteria | cpe:2.3:a:netfoundry:zrok:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.