PT-2025-50277 · Zitadel · Zitadel

Amit-Laish

·

Published

2025-12-08

·

Updated

2026-01-06

·

CVE-2025-67494

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.7.0 and below
Description ZITADEL is an open-source identity infrastructure tool susceptible to an unauthenticated, full-read Server-Side Request Forgery (SSRF) issue. The ZITADEL Login UI (V2) incorrectly trusts the x-zitadel-forward-host header, allowing an unauthenticated attacker to compel the server to make HTTP requests to arbitrary domains. This can lead to data exfiltration and circumvention of network-segmentation controls. The issue enables network pivoting by allowing attackers to map internal infrastructure.
Recommendations Update to version 4.7.1 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2026-00829
CVE-2025-67494
GHSA-7WFC-4796-GMG5
GO-2025-4210
SUSE-SU-2026:0037-1

Affected Products

Zitadel