Openziti is a zero-trust networking platform that consolidates identity-driven access control and encrypted tunneling; its disclosed vulnerabilities cluster around application-layer input handling, particularly cross-site scripting and server-side request forgery in its web-facing components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openziti over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27501HIGH OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form of authentication. Thi | Mar 3, 2025 | 8.6 | 24 | NO | NO |
CVE-2025-27500MEDIUM OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) on the admin panel can be accessed without any form of authen | Mar 3, 2025 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openziti.
Media articles that mention a CVE ID that affects a product developed by Openziti — matched by CVE ID, not by vendor name.