cbcvebase.
CVE-2025-67494
published 2025-12-09

CVE-2025-67494: ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The…

PriorityP357high8.6CVSS 3.1
AVNACLPRNUINSCCHINAN
EPSS
0.45%
36.0th percentile
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.

Affected

9 ranges
VendorProductVersion rangeFixed in
github.comzitadel_zitadel>= 0 < 1.80.0-v2.20.0.20251208091519-4c879b47334e1.80.0-v2.20.0.20251208091519-4c879b47334e
github.comzitadel_zitadel1.83.4 – 1.87.5
github.comzitadel_zitadel>= 1.83.4
github.comzitadel_zitadel>= 4.0.0-rc.1 < 4.7.14.7.1
github.comzitadel_zitadel_v2>= 0 < 1.80.0-v2.20.0.20251208091519-4c879b47334e1.80.0-v2.20.0.20251208091519-4c879b47334e
zitadelzitadel< 1.80.0-v2.20.0.20251208091519-4c879b47334e1.80.0-v2.20.0.20251208091519-4c879b47334e
zitadelzitadel
zitadelzitadel
zitadelzitadel>= 4.0.0 < 4.7.14.7.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.