CVE-2025-67494: ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login

Published Dec 8, 2025
·
Updated

Summary

Zitadel is vulnerable to an unauthenticated, full-read SSRF vulnerability. An unauthenticated remote attacker can force Zitadel into making HTTP requests to arbitrary domains, including internal addresses. The server then returns the upstream response to the attacker, enabling data exfiltration from internal services.

Impact

ZITADEL Login UI (V2) was vulnerable to service URL manipulation through the x-zitadel-forward-host header. The service URL resolution logic treated the header as a trusted fallback for all deployments, including self-hosted instances. This allowed unauthenticated attacker to force the server to make outbound requests and read the responses, reaching internal services, exfiltrating data, and bypassing IP-based or network-segmentation controls. Affected Versions

Systems using the login UI (v2) and running one of the following versions are affected: - v4.x: 4.0.0-rc.1 through 4.7.0

Patches

The vulnerability has been addressed in the latest release. The patch resolves the issue by correctly validating the x-zitadel-forward-host, resp. all forwarded headers against the instance domains and trusted domains. It's no longer used to route traffic to the Zitadel API.

Before you upgrade, ensure that: - the ZITADELAPIURL is set and is pointing to your instance, resp. system in multi-instance deployments. - the HTTP host (or a x-forwarded-host) is passed in your reverse proxy to the login UI. - a x-zitadel-instance-host (or x-zitadel-forward-host) is set in your reverse for multi-instance deployments. If you're running a single instance solution, you don't need to take any actions.

Fixed versions: - 4.x: Upgrade to >=4.7.1

Workarounds

The recommended solution is to update ZITADEL to a patched version.

A ZITADEL fronting proxy can be configured to delete all x-zitadel-forward-host header values or set it to the requested host before sending requests to ZITADEL self-hosted environments.

Questions

If you have any questions or comments about this advisory, please email us at security@zitadel.com

Credits

Thanks to Amit Laish – GE Vernova for finding and reporting the vulnerability.

Other sources

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.

— MITRE

Affected Software

5 affected componentsFixes available
go/github.com/zitadel/zitadel/v2<1.80.0-v2.20.0.20251208091519-4c879b47334e
1.80.0-v2.20.0.20251208091519-4c879b47334e
go/github.com/zitadel/zitadel>=4.0.0-rc.1<4.7.1
4.7.1
go/github.com/zitadel/zitadel>=1.83.4<=1.87.5
go/github.com/zitadel/zitadel<1.80.0-v2.20.0.20251208091519-4c879b47334e
1.80.0-v2.20.0.20251208091519-4c879b47334e
ZITADEL ZITADEL>=4.0.0<4.7.1

Event History

Dec 8, 2025
Advisory Published
via GitHub·10:19 PM
Data Sourced
via GitHub·10:19 PM
DescriptionSeverityWeaknessAffected Software
Dec 9, 2025
CVE Published
via MITRE·10:07 PM
Data Sourced
via MITRE·10:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-67494?

CVE-2025-67494 is classified as a critical vulnerability due to its potential for unauthorized access and data exfiltration.

2

Who is affected by CVE-2025-67494?

CVE-2025-67494 affects Zitadel versions prior to 1.80.0-v2.20.0.20251208091519-4c879b47334e and versions between 4.0.0-rc.1 and 4.7.1.

3

How do I fix CVE-2025-67494?

To remediate CVE-2025-67494, upgrade Zitadel to version 1.80.0-v2.20.0.20251208091519-4c879b47334e or a secure version within the specified range.

4

What type of vulnerability is CVE-2025-67494?

CVE-2025-67494 is an unauthenticated server-side request forgery (SSRF) vulnerability.

5

What can an attacker do with CVE-2025-67494?

An attacker exploiting CVE-2025-67494 can make Zitadel send HTTP requests to arbitrary domains, potentially leading to data leakage.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203