CVE-2025-67494 is an unauthenticated, full-read Server-Side Request Forgery (SSRF) vulnerability affecting ZITADEL versions 4.7.0 and below. An attacker can manipulate the x-zitadel-forward-host header to force the server to make HTTP requests to arbitrary internal or external domains, allowing for data exfiltration and bypassing network segmentation. This vulnerability is rated as High severity with a CVSS score of 8.6, indicating a network-based attack with low complexity, requiring no privileges or user interaction, and resulting in high confidentiality impact. The EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.7.1CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.