CRITICAL🇵🇱 Wersja polska

CVE-2025-67494

CVSS 9.3v3.1pub. 2025-12-09upd. 2025-12-19

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.

🤖 AI Analysis
How it works

ZITADEL Login UI (V2) unconditionally treats the HTTP header `x-zitadel-forward-host` as a trusted target source for all deployments, including self-hosted installations. An unauthenticated attacker can send a request with an arbitrarily set `x-zitadel-forward-host` header pointing to an internal network address or external domain. The ZITADEL server will execute the request to the specified address and return its contents to the attacker, enabling full-read SSRF.

Impact

An attacker can gain unauthorized access to internal network resources that are not publicly accessible, exfiltrate sensitive data, and bypass network segmentation mechanisms and access controls based on network topology.

Mitigation & patch

Update ZITADEL to version 4.7.1, where the issue has been fixed. The patch is available in the project's GitHub repository (commit 4c879b47334e01d4fcab921ac1b44eda39acdb96). Until the update is applied, it is recommended to restrict access to the Login UI interface at the firewall or reverse proxy level and monitor unusual outgoing requests from the server.

Who is affected

ZITADEL in versions 4.7.0 and lower — affects all deployments, including self-hosted installations using ZITADEL Login UI V2.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
  • Zitadel

    APP
    Zitadel
    4.0.0 – 4.7.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRFAuth Bypass
CWE
References

Related vulnerabilities

CVE-2026-29191CRITICAL9.3PL ✓same product

XSS w Zitadel Login V2 — możliwe przejęcie konta przez /saml-post

CVE-2025-27507CRITICAL9.0PL ✓same product

IDOR w Zitadel Admin API umożliwia modyfikację wrażliwych ustawień

CVE-2026-44671HIGH7.5same product

ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerabil...

CVE-2026-32131HIGH7.7same product

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel'...

CVE-2026-32130HIGH7.5same product

ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provid...