CVE-2026-105214
Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, so attackers can register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.
| CWE | CWE-918 |
| Vendor | zitadel |
| Product | zitadel |
| Published | Oct 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for zitadel zitadel
Be the first to know when new unknown vulnerabilities affecting zitadel zitadel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
zitadel / zitadel
0 < 4.16.2
References
Credits
livio-a IAM-marco ๐ IbrahimMrpl ๐ kanywst