Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password reset confirmation link. This link, containing a secret code, is then emailed to the user. If an attacker can manipulate these headers (e.g., via host header injection), they could cause ZITADEL to generate a password reset link pointing to a malicious domain controlled by the attacker. If the user clicks this manipulated link in the email, the secret reset code embedded in the URL can be captured by the attacker. This captured code could then be used to reset the user's password and gain unauthorized access to their account. It's important to note that this specific attack vector is mitigated for accounts that have Multi-Factor Authentication (MFA) or Passwordless authentication enabled. This vulnerability is fixed in 4.6.0, 3.4.3, and 2.71.18.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Zitadel Zitadel zitadel | |
| Vendors & Products | Zitadel Zitadel zitadel | 
Wed, 29 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 29 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password reset confirmation link. This link, containing a secret code, is then emailed to the user. If an attacker can manipulate these headers (e.g., via host header injection), they could cause ZITADEL to generate a password reset link pointing to a malicious domain controlled by the attacker. If the user clicks this manipulated link in the email, the secret reset code embedded in the URL can be captured by the attacker. This captured code could then be used to reset the user's password and gain unauthorized access to their account. It's important to note that this specific attack vector is mitigated for accounts that have Multi-Factor Authentication (MFA) or Passwordless authentication enabled. This vulnerability is fixed in 4.6.0, 3.4.3, and 2.71.18. | |
| Title | ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection | |
| Weaknesses | CWE-601 CWE-640 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-29T18:30:14.999Z
Updated: 2025-10-29T19:35:39.237Z
Reserved: 2025-10-27T15:26:14.126Z
Link: CVE-2025-64101
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-29T19:35:35.499Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-29T19:15:38.763
Modified: 2025-10-30T15:03:13.440
Link: CVE-2025-64101
 Redhat
                        Redhat
                    No data.