Github.com/zitadel/zitadel/v2
This hub aggregates every CVE we track for Github.com/zitadel/zitadel/v2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
14
CVEs tracked
5
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7CRITICAL5MEDIUM2
Monthly trend
0
3
0
0
0
0
0
1
0
1
0
0
0
0
3
0
2
0
1
3
0
0
0
0
2024-082026-07
Latest CVEs
The 14 most recently published vulnerabilities affecting Github.com/zitadel/zitadel/v2.
- CVE-2026-29193ZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V28.2
- CVE-2026-29192ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover7.7
- CVE-2026-29191ZITADEL: 1-Click Account Takeover via XSS in /saml-post Endpoint9.3
- CVE-2026-27945ZITADEL has potential SSRF via Actions6.5
- CVE-2025-67495ZITADEL Vulnerable to Account Takeover via DOM-Based XSS in Zitadel V2 Login8.0
- CVE-2025-67494ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login9.3
- CVE-2025-64103Zitadel Bypass Second Authentication Factor9.8
- CVE-2025-64102Zitadel allows brute-forcing authentication factors9.8
- CVE-2025-64101ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection8.1
- CVE-2025-48936ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection8.1
- CVE-2025-27507IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations9.0
- CVE-2024-46999User Grant Deactivation not Working in Zitadel7.3
- CVE-2024-47000Service Users Deactivation not Working in Zitadel8.1
- CVE-2024-47060Unauthorized Access After Organization or Project Deactivation in Zitadel4.3
Product normalization is registry-driven with AI assist and human review. How it works