Open Redirect Affecting github.com/zitadel/zitadel/internal/api/oidc package, versions <4.7.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.32% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMZITADELZITADELINTERNALAPIOIDC-14236445
  • published10 Dec 2025
  • disclosed8 Dec 2025
  • creditamit-laish

Introduced: 8 Dec 2025

CVE-2026-29067  (opens in a new tab)
CWE-601  (opens in a new tab)

How to fix?

Upgrade github.com/zitadel/zitadel/internal/api/oidc to version 4.7.1 or higher.

Overview

github.com/zitadel/zitadel/internal/api/oidc is a package for identity infrastructure

Affected versions of this package are vulnerable to Open Redirect via manipulation of the Forwarded or X-Forwarded-Host headers used to construct password reset confirmation links. An attacker can gain unauthorized access to user accounts by tricking users into clicking a malicious password reset link, allowing the attacker to capture the secret reset code and reset the user's password.

Note: This is only exploitable if Multi-Factor Authentication (MFA) or Password-less authentication is not enabled for the targeted account.

Workaround

This vulnerability can be mitigated by configuring a fronting proxy to delete all forwarded header values or set them to the requested host before sending requests to self-hosted environments.

CVSS Base Scores

version 4.0
version 3.1