Impact
ZITADEL is an open‑source identity‑management platform. Versions 4.0.0-rc.1 through 4.15.1 contain an SSRF flaw whereby HTTP notification channels, OIDC BackChannel Logout, and SAML metadata URL fetches fail to validate user‑supplied URLs against a protected denylist, allowing the server to request arbitrary URLs—including loopback, internal IP, link‑local, or redirected endpoints via DNS rebinding, redirects, or protocol downgrades. The flaw does not provide remote code execution but can expose internal services and data. This issue was fixed in ZITADEL 4.15.2.
Affected Systems
Versions of ZITADEL from 4.0.0-rc.1 through 4.15.1 are affected, while the fix was introduced in v4.15.2. The platform is the open‑source ZITADEL identity‑management solution.
Risk and Exploitability
The CVSS score of 2.3 classifies the issue as low severity, and the EPSS score is < 1 %. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is a malicious user supplying a crafted URL in the application’s configuration or in a notification payload, which the server then resolves and fetches. Though the exploit does not lead to code execution, it can expose internal services and data through the SSRF channel.
OpenCVE Enrichment
Github GHSA