CVE-2026-105214: Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification
Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, so attackers can register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to be able to register a domain for organization domain HTTP verification and configure that domain to redirect requests. The redirect can point the server-side verification request at internal destinations.
What systems or services could be exposed through the vulnerable request?
The vulnerable verification fetch can be redirected to loopback addresses, internal network resources, or cloud metadata addresses. This can allow port scanning and internal network mapping from the Zitadel server's network position.