Skip to content

x/vulndb: potential Go vuln in github.com/zitadel/zitadel/v2: GHSA-xrw9-r35x-x878 #4085

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-xrw9-r35x-x878 references a vulnerability in the following Go modules:

Module
github.com/zitadel/zitadel

Description:

Summary

A vulnerability in Zitadel allowed brute-force attack on OTP, TOTP and password allowing to impersonate the attacked user.

Impact

An attacker can perform an online brute-force attack on OTP, TOTP, and passwords. While Zitadel allows preventing online brute force attacks in scenarios like TOTP, Email OTP, or passwords using a lockout mechanism. The mechanism is not enabled by default and can cause a denial of service for the corresponding user if enabled. Additionally, the mitigation strategies were not fully implemented in the more recent resource-based APIs.

Affected V...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/zitadel/zitadel
      non_go_versions:
        - fixed: 2.71.18
      vulnerable_at: 1.87.5
summary: Zitadel allows brute-forcing authentication factors in github.com/zitadel/zitadel
cves:
    - CVE-2025-64102
ghsas:
    - GHSA-xrw9-r35x-x878
references:
    - advisory: https://github.com/advisories/GHSA-xrw9-r35x-x878
    - advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-xrw9-r35x-x878
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-64102
    - fix: https://github.com/zitadel/zitadel/commit/b8db8cdf9cc8ea13f461758aef12457f8b7d972a
source:
    id: GHSA-xrw9-r35x-x878
    created: 2025-10-29T23:01:25.567051357Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions