← Back to CVE List
CVE-2026-105214NVD
Vulnerability Summary
Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, so attackers can register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.
CVSS v4.0 Base Metrics — Score 2.3 (LOW)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- zitadel zitadel < 4.16.2
- zitadel zitadel 4.16.2