VYPR

Zitadel

by Zitadel

Source repositories

CVEs (59)

  • CVE-2026-29067HigMar 7, 2026
    risk 0.46cvss 8.1epss 0.00

    ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for…

  • CVE-2025-64101HigOct 29, 2025
    risk 0.46cvss 8.1epss 0.00

    Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the…

  • CVE-2025-48936HigMay 30, 2025
    risk 0.46cvss 8.1epss 0.00

    Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the…

  • CVE-2024-28855HigMar 18, 2024
    risk 0.46cvss 8.1epss 0.01

    ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the `text/template` instead of the `html/template` package, the Login UI did not sanitize input parameters prior to versions 2.47.3, 2.46.1, 2.45.1,…

  • CVE-2025-67495HigDec 9, 2025
    risk 0.45cvss 8.0epss 0.00

    ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint insecurely routes to a value that is supplied in the post_logout_redirect GET parameter. As a…

  • CVE-2025-46815HigMay 6, 2025
    risk 0.45cvss 8.0epss 0.00

    The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for authentication, known as idp intents. Following a successful idp intent, the client receives an id and token on a…

  • CVE-2026-29192HigMar 7, 2026
    risk 0.43cvss 7.7epss 0.00

    ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via Default URI Redirect. This issue has been patched in version 4.12.0.

  • CVE-2026-44671HigMay 14, 2026
    risk 0.42cvss 7.5epss 0.00

    ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, which fails to properly escape user-provided usernames before incorporating them into LDAP search…

  • CVE-2024-49757HigOct 25, 2024
    risk 0.42cvss 7.5epss 0.03

    The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option…

  • CVE-2024-28197HigMar 11, 2024
    risk 0.42cvss 7.5epss 0.00

    Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie was handled according to best practices, it was accessible on subdomains of the ZITADEL instance. An attacker could take…

  • CVE-2026-55672HigJul 10, 2026
    risk 0.41cvss 7.4epss 0.00

    ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify that the requesting client matches the client that initiated the authorization flow, allowing…

  • CVE-2023-47111HigNov 8, 2023
    risk 0.40cvss 7.3epss 0.01

    ZITADEL provides identity infrastructure. ZITADEL provides administrators the possibility to define a `Lockout Policy` with a maximum amount of failed password check attempts. On every failed password check, the amount of failed checks is compared against the configured maximum.…

  • CVE-2026-27946MedFeb 26, 2026
    risk 0.35cvss 6.5epss 0.00

    ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process. The patch in versions…

  • CVE-2026-27945MedFeb 26, 2026
    risk 0.35cvss 6.5epss 0.00

    ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta in 3.0.0 and GA in 4.0.0) is a webhook based approach to allow developers act on API request to Zitadel and customize flows such the issue of a token. Zitadel's…

  • CVE-2024-32868MedApr 26, 2024
    risk 0.35cvss 6.5epss 0.00

    ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed password check attempts, there…

  • CVE-2024-29892MedMar 27, 2024
    risk 0.33cvss 6.1epss 0.01

    ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. For example it would be possible to set the claim `urn:zitadel:iam:user:resourceowner:name`. To…

  • CVE-2024-49753MedOct 25, 2024
    risk 0.31cvss 5.9epss 0.01

    Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1).…

  • CVE-2023-22492MedJan 11, 2023
    risk 0.31cvss 5.9epss 0.01

    ZITADEL is a combination of Auth0 and Keycloak. RefreshTokens is an OAuth 2.0 feature that allows applications to retrieve new access tokens and refresh the user's session without the need for interacting with a UI. RefreshTokens were not invalidated when a user was locked or…

  • CVE-2024-39683MedJul 3, 2024
    risk 0.30cvss 5.7epss 0.01

    ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without…

  • CVE-2026-76081MedSep 14, 2026
    risk 0.29cvss 5.5epss 0.00

    ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects User Grants on Granted…