PT-2025-44341 · Zitadel · Zitadel

Published

2025-10-29

·

Updated

2025-11-07

·

CVE-2025-64101

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zitadel versions prior to 4.6.0 Zitadel versions prior to 3.4.3 Zitadel versions prior to 2.71.18
Description Zitadel's password reset mechanism is susceptible to manipulation through the Forwarded or X-Forwarded-Host headers in incoming requests. The system uses these headers to build the URL for the password reset confirmation link. An attacker can exploit this by injecting a malicious domain into these headers, causing the generated link to point to a site under their control. If a user clicks this manipulated link, the attacker can capture the secret reset code and use it to gain unauthorized access to the user's account. This issue does not affect accounts with Multi-Factor Authentication (MFA) or Passwordless authentication enabled.
Recommendations Update to Zitadel version 4.6.0 or later. Update to Zitadel version 3.4.3 or later. Update to Zitadel version 2.71.18 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64101
GHSA-MWMH-7PX9-4C23
GO-2025-4084
OPENSUSE-SU-2025:15710-1

Affected Products

Zitadel