Description
Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, so attackers can register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.
Published: 2026-10-04
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery allowing internal resource access
Action: Patch
AI Analysis

Impact

Zitadel before version 4.16.2 contains a server‑side request forgery flaw that lets an attacker trigger HTTP requests to internal or cloud‑metadata addresses via organization domain HTTP verification. The vulnerability arises because the application uses Go's default http.Get instead of a protected HTTP client when fetching challenge data. An attacker can therefore register a domain that redirects to a loopback, internal, or cloud‑metadata address, causing the server to perform arbitrary requests. The impact is the ability to probe internal network services and map internal resources, which can enable further reconnaissance or attacks on the infrastructure.

Affected Systems

Any installation of Zitadel with a version earlier than 4.16.2 is affected, regardless of other configuration details.

Risk and Exploitability

The CVSS score is 2.3, indicating low severity. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog. Attackers likely need the ability to register organization domains, which means the exploitation surface may be limited to users with that privilege. The SSRF flaw allows remote actors to cause the server to reach internal endpoints, potentially leaking information about internal hosts, open ports, and services. Because the vulnerability is low severity, the exploitation probability is expected to be low, but successful exploitation could provide valuable reconnaissance data for future attacks.

Generated by OpenCVE AI on October 4, 2026 at 15:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Zitadel 4.16.2 or later
  • Restrict organization domain verification to trusted domains only
  • Implement network segmentation to isolate the Zitadel server from sensitive internal resources

Generated by OpenCVE AI on October 4, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, so attackers can register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.
Title Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification
First Time appeared Zitadel
Zitadel zitadel
Weaknesses CWE-918
CPEs cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
Vendors & Products Zitadel
Zitadel zitadel
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T13:10:06.642Z

Reserved: 2026-10-04T13:02:21.188Z

Link: CVE-2026-105214

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T15:16:32.843

Modified: 2026-10-04T15:16:32.950

Link: CVE-2026-105214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T15:30:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)