๐Ÿ” CVE Alert

CVE-2026-105214

UNKNOWN 0.0

Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, so attackers can register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.

CWE CWE-918
Vendor zitadel
Product zitadel
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for zitadel zitadel

Be the first to know when new unknown vulnerabilities affecting zitadel zitadel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

zitadel / zitadel
0 < 4.16.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zitadel/zitadel/security/advisories/GHSA-93hm-8q29-c8cr vulncheck.com: https://www.vulncheck.com/advisories/zitadel-before-4.16.2-ssrf-via-organization-domain-http-verification

Credits

livio-a IAM-marco ๐Ÿ” IbrahimMrpl ๐Ÿ” kanywst