PT-2025-50277 · Zitadel · Zitadel

·

CVE-2025-67494

·

Published

2025-12-08

·

Updated

2026-07-30

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.7.0 and below
Description ZITADEL is an open-source identity infrastructure tool susceptible to an unauthenticated, full-read Server-Side Request Forgery (SSRF) issue. The ZITADEL Login UI (V2) incorrectly trusts the x-zitadel-forward-host header, allowing an unauthenticated attacker to compel the server to make HTTP requests to arbitrary domains. This can lead to data exfiltration and circumvention of network-segmentation controls. The issue enables network pivoting by allowing attackers to map internal infrastructure.
Recommendations Update to version 4.7.1 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00829
CVE-2025-67494
GHSA-7WFC-4796-GMG5
GO-2025-4210
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0037-1

Affected Products

Zitadel