CVE-2025-64101 PUBLISHED CVSS 8.100000381469727 HIGH

ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection

EPSS 0.14% · 33.4th percentile

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
0.14%
33.4th percentile

Affected Products

VendorProductVersions
zitadelzitadel>= 4.0.0-rc.1, < 4.6.0, >= 3.0.0-rc.1, < 3.4.3, >= 2.0.0, < 2.71.18
github.comzitadel/zitadel/v22.0.0, 0

Timeline

References

Open in Interactive Console →