Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zitadel — Vulnerabilities & Security Advisories 58

Browse all 58 CVE security advisories affecting zitadel. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Zitadel is an open-source identity and access management platform designed to provide authentication, authorization, and user lifecycle management for modern applications. Its architecture supports multi-tenant environments, enabling organizations to manage user identities securely across diverse services. Historically, the platform has been associated with forty-seven recorded Common Vulnerabilities and Exposures (CVEs), reflecting a significant attack surface. These vulnerabilities predominantly involve privilege escalation, cross-site scripting, and improper access control mechanisms, allowing attackers to bypass authentication or access unauthorized resources. While no massive, widely publicized data breaches have been definitively attributed to these specific flaws, the high volume of CVEs indicates persistent security challenges in its codebase. Developers are urged to apply patches promptly, as the recurring nature of these issues suggests systemic weaknesses in input validation and permission handling that require rigorous maintenance and continuous security auditing to mitigate risks effectively.

Found 58 results / 58Clear Filters
Top products by zitadel: zitadel
HighCVE-2024-56032026-07-30
Users Can Self-Verify Email/Phone via API · Advisory · zitadel/zitadel · GitHub
Unknown9051022026-07-30
Release v3.4.11 · zitadel/zitadel · GitHub
High2026-07-11
fix(login): guard defaultRedirectUri in OIDC/SAML FailedPrecondition … · zitadel/zitadel@0382659 · GitHub
High2026-07-11
fix: added client and scope validation for token exchange · zitadel/zitadel@e2886a6 · GitHub
High2026-07-11
fix: always validate exp and iat claims of JWT IdPs · zitadel/zitadel@4925fab · GitHub
High2026-07-11
fix: always validate exp and iat claims of JWT IdPs · zitadel/zitadel@d1c3aa8 · GitHub
High2026-07-11
Release v3.4.12 · zitadel/zitadel · GitHub
HighCVE-2024-56662026-07-11
Auto-linking by email: IdP-side email verification is not checked · Advisory · zitadel/zitadel · GitHub
High2026-07-11
Release v4.15.2 · zitadel/zitadel · GitHub
HighCVE-2025-566642026-07-11
Missing Issued-At (`iat`) Freshness Validation in JWT IdP Provider · Advisory · zitadel/zitadel · GitHub
High2026-07-11
fix: ensure external user's email is verified before auto-linking · zitadel/zitadel@c97012f · GitHub
MediumCVE-2024-556702026-07-11
Cross-Tenant User Leakage via Recycled Identifiers · Advisory · zitadel/zitadel · GitHub
Unknown2026-07-11
fix(eventstore): allow overwriting resource owner of events by adlerhurst · Pull Request #12261 · zitadel/zitadel · GitH
High2026-07-11
fix(eventstore): allow overwriting resource owner of events (#12261) · zitadel/zitadel@a939b84 · GitHub
HighCVE-2026-556722026-07-11
Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
High2026-07-11
fix: client_id verification during code exchange and refresh token flows · zitadel/zitadel@5624030 · GitHub
Critical2026-07-11
fix: use protected http client for outgoing connections · zitadel/zitadel@b6f7808 · GitHub
High2026-07-11
fix: client_id verification during code exchange and refresh token flows · zitadel/zitadel@5b1708e · GitHub
HighCVE-2024-55692026-07-11
Missing Token Audience Validation (`aud`) in JWT IdP Provider · Advisory · zitadel/zitadel · GitHub
HighCVE-2026-279462026-02-26
Users Can Self-Verify Email/Phone via UpdateHumanUser API · Advisory · zitadel/zitadel · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with zitadel. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.