{"id":"CVE-2026-45568","aliases":["GHSA-jh67-hwqw-m5r7","PYSEC-2026-577"],"url":"https://o3.security/vulnerability/CVE-2026-45568","summary":"zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths","details":"## Summary\n\nAlice exposes a Python SDK `ProxyShare` with a fixed target URL. Bob sends a request to the share with an absolute URL in the path. The Flask handler passes that path to `urllib.parse.urljoin`, which replaces Alice's configured target host with Bob's host and returns the server-side response to Bob.\n\n## Details\n\nThe Python SDK proxy route accepts every path under the share:\n\n```python\n@app.route('/', defaults={'path': ''}, methods=['GET', 'POST', 'PUT', 'DELETE', 'PATCH', 'OPTIONS'])\n@app.route('/<path:path>', methods=['GET', 'POST', 'PUT', 'DELETE', 'PATCH', 'OPTIONS'])\ndef proxy(path):\n```\n\nIt constructs the outbound URL with `urljoin` and then sends the request:\n\n```python\nurl = urllib.parse.urljoin(self.target, path)\nresp = requests.request(\n    method=request.method,\n    url=url,\n    headers={key: value for (key, value) in request.headers\n             if key.lower() not in HOP_BY_HOP_HEADERS},\n    data=request.get_data(),\n    cookies=request.cookies,\n    allow_redirects=False,\n    stream=True,\n    verify=self.verify_ssl\n)\n```\n\nWhen `path` is `[http://127.0.0.1:19190/metadata`](http://127.0.0.1:19190/metadata%60), `urljoin(self.target, path)` returns `[http://127.0.0.1:19190/metadata`](http://127.0.0.1:19190/metadata%60). The proxy sends the request to Bob's chosen URL rather than Alice's target.","published":"2026-07-16T16:45:00.305Z","modified":"2026-08-12T03:51:23.780741405Z","cvss":null,"epss":{"score":0.00361,"percentile":0.29218,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"zrok","fixedVersion":null}],"fix":{"url":"https://github.com/openziti/zrok/commit/7c1dc3ecd1c89d8cd2e845a72c3878bd2d31b4fe","label":"openziti/zrok@7c1dc3e"},"references":[{"type":"WEB","url":"https://github.com/openziti/zrok/releases/tag/v2.0.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45568.json"},{"type":"ADVISORY","url":"https://github.com/openziti/zrok/security/advisories/GHSA-jh67-hwqw-m5r7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45568"},{"type":"FIX","url":"https://github.com/openziti/zrok/commit/7c1dc3ecd1c89d8cd2e845a72c3878bd2d31b4fe"},{"type":"PACKAGE","url":"https://github.com/openziti/zrok"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:23.780741405Z"}}