VYPR

Zitadel

by Zitadel

Source repositories

CVEs (59)

  • CVE-2024-47060MedSep 20, 2024
    risk 0.28cvss 4.3epss 0.00

    Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across other organizations can still log in and access through these applications, leading to…

  • CVE-2024-41952MedJul 31, 2024
    risk 0.28cvss 5.3epss 0.01

    Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password prompt even if the user doesn't…

  • CVE-2024-32967MedMay 1, 2024
    risk 0.28cvss 5.3epss 0.01

    Zitadel is an open source identity management system. In case ZITADEL could not connect to the database, connection information including db name, username and db host name could be returned to the user. This has been addressed in all supported release branches in a point…

  • CVE-2026-33132MedMar 20, 2026
    risk 0.27cvss 5.3epss 0.00

    ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users to bypass organization enforcement during authentication. Zitadel allows applications to enforce an organzation context during authentication using scopes…

  • CVE-2026-23511MedJan 15, 2026
    risk 0.27cvss 5.3epss 0.00

    ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating…

  • CVE-2023-44399MedOct 10, 2023
    risk 0.27cvss 5.3epss 0.01

    ZITADEL provides identity infrastructure. In versions 2.37.2 and prior, ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. While this settings was properly working during the…

  • CVE-2026-56666MedJul 10, 2026
    risk 0.24cvss 4.8epss 0.00

    ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the same email before auto-linking by email,…

  • CVE-2026-27840MedFeb 26, 2026
    risk 0.21cvss 4.3epss 0.00

    ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.0, opaque OIDC access tokens in the v2 format truncated to 80 characters are still considered valid. Zitadel uses a symmetric AES encryption for opaque…

  • CVE-2025-67717MedDec 11, 2025
    risk 0.21cvss 4.3epss 0.00

    ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 disclose the total number of instance users to authenticated users, regardless of their specific permissions. While this does not leak individual user data or PII,…

  • CVE-2024-41953MedJul 31, 2024
    risk 0.21cvss 4.3epss 0.01

    Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be entered by users or administrators. Due to a missing output sanitization, these emails could include…

  • CVE-2026-56665MedJul 10, 2026
    risk 0.20cvss 4.2epss 0.00

    ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity management platform. From 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1, ZITADEL's external JWT Identity Provider validation in…

  • CVE-2026-56664MedJul 10, 2026
    risk 0.20cvss 4.2epss 0.00

    ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits the iat claim, allowing…

  • CVE-2026-55669MedJul 10, 2026
    risk 0.20cvss 4.2epss 0.00

    ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying…

  • CVE-2026-55671LowJul 10, 2026
    risk 0.08cvss —epss 0.00

    ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification channels, OIDC BackChannel Logout, and SAML metadata URL fetches do not consistently validate user-defined URLs against protected denylist handling, allowing…

  • CVE-2026-55670LowJul 10, 2026
    risk 0.08cvss —epss 0.00

    ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organization to be provisioned under…

  • CVE-2026-56667HigJul 10, 2026
    risk 0.00cvss 7.3epss 0.00

    ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPrecondition error paths return loginSettings.defaultRedirectUri to router.push without applying the isSafeRedirectUri check, allowing an organization or instance…

  • CVE-2025-57770MedAug 22, 2025
    risk 0.00cvss 5.3epss 0.00

    The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Versions 4.0.0 to 4.0.2, 3.0.0 to 3.3.6, and all versions prior to 2.71.15 are vulnerable to a username enumeration issue in the login interface. The login UI…

  • CVE-2025-31124MedMar 31, 2025
    risk 0.00cvss 5.3epss 0.01

    Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password prompt even if the user doesn't…

  • CVE-2025-31123HigMar 31, 2025
    risk 0.00cvss 8.7epss 0.00

    Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of the JWT key when used for Authorization Grants. This allows an attacker with…

Page 3 of 3