Server-side Request Forgery (SSRF) Affecting github.com/zitadel/zitadel/internal/net package, versions >=2.59.0 <4.11.1


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.23% (14th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMZITADELZITADELINTERNALNET-15369729
  • published3 Mar 2026
  • disclosed26 Feb 2026
  • creditMartin Tschirsich, Joud Zakharia, Christopher Baumann

Introduced: 26 Feb 2026

CVE-2026-27945  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade github.com/zitadel/zitadel/internal/net to version 4.11.1 or higher.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the Actions V2 webhook. An attacker can access internal network resources and gather information about internal services by specifying target URLs that resolve to local hosts or internal IP addresses.

Workaround

This vulnerability can be mitigated by setting network policies or firewall rules in the infrastructure to prevent actions from accessing unintended endpoints.

CVSS Base Scores

version 4.0
version 3.1