Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-33529

Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the configuration import endpoint allows an authenticated user to write arbitrary files outside the config directory, which can lead to RCE by creating a plugin. Version 3.3.2 patches the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.9%
CVSS Severity
CVSS v3 Score 3.3
Products affected by CVE-2026-33529
  • Zoraxy » Zoraxy » Version: Any
    cpe:2.3:a:zoraxy:zoraxy:*


Contact Us

Shodan ® - All rights reserved