Please refer to the openziti-security repository for details of the security policies and processes for this repository.
Security: openziti/ziti
Security
SECURITY.md
-
Router link listener binds peer identity from the whole presented certificate chain, allowing an enrolled router to impersonate another router on a linkGHSA-hhm9-wf63-g7qj published
Aug 21, 2026 by plorenzModerate -
Controller does not validate the API session token when creating circuits via CreateCircuitV3, allowing a router to dial on behalf of any identityGHSA-7868-235p-7497 published
Aug 21, 2026 by plorenzModerate -
Control-channel connections with a channel-type header bypass router certificate and identity verificationGHSA-cc5m-7mhm-xh9f published
Aug 12, 2026 by plorenzModerate -
Improper peer certificate validation allows identity spoofing on controller cluster, router links, and metrics TLS connectionsGHSA-mrpr-756c-xm47 published
Aug 12, 2026 by plorenzCritical -
OpenZiti controller: JWT enrollment via ziti-token-issuer-id header skips audience and issuer validation (cross-audience token enrollment bypass)GHSA-4h58-w989-xgg4 published
Aug 21, 2026 by plorenzModerate -
OpenZiti edge router MFA posture nil-pointer panic causing authenticated router DoSGHSA-354c-gpg9-j988 published
Aug 21, 2026 by plorenzModerate -
Unauthenticated Memory Exhaustion via Unbounded Pre-Auth Request Body BufferingGHSA-q8g9-jc4c-jp6q published
Aug 21, 2026 by plorenzHigh -
Legacy Enrollment Path Doubles Per-Request Memory Allocation, Amplifying Memory Exhaustion DoSGHSA-j952-6x8x-jmj6 published
Aug 21, 2026 by plorenzHigh -
Authenticated Users Can Enumerate All API Session Certificates Across All IdentitiesGHSA-6v5r-p2wr-q492 published
Aug 21, 2026 by plorenzModerate -
SSRF via Unsanitized JWKS Endpoint URL in External JWT Signer ConfigurationGHSA-whjr-3j94-gw3c published
Aug 21, 2026 by plorenzModerate
Learn more about advisories related to openziti/ziti in the GitHub Advisory Database