Skip to content

x/vulndb: potential Go vuln in github.com/zitadel/zitadel/v2: GHSA-mwmh-7px9-4c23 #4084

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-mwmh-7px9-4c23 references a vulnerability in the following Go modules:

Module
github.com/zitadel/zitadel

Description:

Impact

A potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password reset confirmation link. This link, containing a secret code, is then emailed to the user.

If an attacker can manipulate these headers (e.g., via host header injection), they could cause ZITADEL to generate a password reset link pointing to a malicious domain controlled by the attacker. If the user clicks this manipulated link in the email, the secret reset code embedded in the URL can be capt...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/zitadel/zitadel
      non_go_versions:
        - fixed: 2.71.18
      vulnerable_at: 1.87.5
summary: ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection in github.com/zitadel/zitadel
cves:
    - CVE-2025-64101
ghsas:
    - GHSA-mwmh-7px9-4c23
references:
    - advisory: https://github.com/advisories/GHSA-mwmh-7px9-4c23
    - advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-mwmh-7px9-4c23
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-64101
    - fix: https://github.com/zitadel/zitadel/commit/72a5c33e6ac302b978d564bd049f9364f5a989b1
source:
    id: GHSA-mwmh-7px9-4c23
    created: 2025-10-29T23:01:24.497296923Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions