CVE-2026-105214
Deferred Deferred - Pending Action

Server-Side Request Forgery in ZITADEL Before 4.16.2

Vulnerability report for CVE-2026-105214, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, so attackers can register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
zitadel zitadel to 4.16.2 (exc)
zitadel zitadel From 3.0.0 (inc) to 3.4.13 (inc)
zitadel zitadel From 4.0.0 (inc) to 4.16.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105214 is a Server-Side Request Forgery (SSRF) vulnerability in Zitadel versions before 4.16.2. It allows attackers to make the server request internal resources by exploiting the organization domain HTTP verification process. Attackers register domains that redirect to loopback, internal, or cloud metadata addresses, enabling them to scan ports and map internal networks.

Detection Guidance

To detect this SSRF vulnerability in Zitadel, check if your system is running versions before 4.16.2. Verify if domain verification uses Go's default http.Get instead of a protected client. Monitor network logs for unusual outbound requests to loopback, internal, or cloud metadata addresses like 169.254.169.254.

Impact Analysis

This vulnerability could allow attackers to scan internal networks, map internal services, and interact with unauthorized internal systems. Exploitation requires an attacker to control a domain that redirects to sensitive addresses like loopback or cloud metadata endpoints. The impact is limited by the need for a specific challenge token.

Compliance Impact

This SSRF vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized access to internal systems and data. Attackers could map internal networks, scan ports, or interact with internal services, which may lead to data breaches or unauthorized data exposure. Such incidents could violate GDPR's data protection requirements or HIPAA's safeguards for protected health information.

Mitigation Strategies

Upgrade Zitadel to version 4.16.2 or later immediately. If using 3.x, upgrade to 4.16.2 as no patch is available for 3.x. Implement network policies to block outbound connections to internal networks and cloud metadata endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105214. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart