Github.com/zitadel/zitadel
This hub aggregates every CVE we track for Github.com/zitadel/zitadel, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
31
CVEs tracked
6
Critical
12
High
0
In CISA KEV
Severity distribution
MEDIUM13HIGH12CRITICAL6
Monthly trend
0
0
2
0
0
0
0
1
0
2
0
0
0
0
2
1
3
1
2
3
0
0
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Github.com/zitadel/zitadel.
- CVE-2026-29193ZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V28.2
- CVE-2026-29192ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover7.7
- CVE-2026-29191ZITADEL: 1-Click Account Takeover via XSS in /saml-post Endpoint9.3
- CVE-2026-27946ZITADEL Users Can Self-Verify Email/Phone via UpdateHumanUser API6.5
- CVE-2026-27840ZITADEL's truncated opaque tokens are still valid4.3
- CVE-2026-23511ZITADEL has a user enumeration vulnerability in Login UIs5.3
- CVE-2025-67717Zitadel Discloses the Total Number of Instance Users4.3
- CVE-2025-67495ZITADEL Vulnerable to Account Takeover via DOM-Based XSS in Zitadel V2 Login8.0
- CVE-2025-67494ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login9.3
- CVE-2025-64717ZITADEL vulnerable to Account Takeover with deactivated Instance IdP9.8
- CVE-2025-64103Zitadel Bypass Second Authentication Factor9.8
- CVE-2025-64102Zitadel allows brute-forcing authentication factors9.8
- CVE-2025-48936ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection8.1
- CVE-2025-46815ZITADEL Allows IdP Intent Token Reuse8.0
- CVE-2025-27507IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations9.0
Product normalization is registry-driven with AI assist and human review. How it works