Netfoundry maintains a focused product portfolio centered on zrok, a zero-trust sharing and tunneling platform that simplifies secure access to internal applications and services. The recurring vulnerability signal spans access-control issues, output-encoding and path-traversal weaknesses, and cross-site scripting flaws that reflect the authentication and input-handling demands of web-facing proxy and sharing infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netfoundry over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45568CRITICAL zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path | Jul 16, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-45576HIGH zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../out | Jul 16, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-42275HIGH zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexi | May 8, 2026 | 8.7 | 33 | NO | NO |
CVE-2026-40303HIGH zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls | Apr 17, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-40302MEDIUM zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escapin | Apr 17, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-40304MEDIUM zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its owner | Apr 17, 2026 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netfoundry.
Media articles that mention a CVE ID that affects a product developed by Netfoundry — matched by CVE ID, not by vendor name.