
github.com/zitadel/zitadel
go · Repository · Package
Security Advisories for github.com/zitadel/zitadel in go
High
4 months ago
ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection
go
github.com/zitadel/zitadel/v2, github.com/zitadel/zitadel
Critical
7 months ago
IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations
go
github.com/zitadel/zitadel, github.com/zitadel/zitadel/v2
Moderate
11 months ago
Denied Host Validation Bypass in Zitadel Actions
go
github.com/zitadel/zitadel
Moderate
about 1 year ago
ZITADEL "ignoring unknown usernames" vulnerability
go
github.com/zitadel/zitadel
Moderate
about 1 year ago
ZITADEL has improper HTML sanitization in emails and Console UI
go
github.com/zitadel/zitadel
Moderate
about 1 year ago
ZITADEL Vulnerable to Session Information Leakage
go
github.com/zitadel/zitadel
Moderate
over 1 year ago
Zitadel exposing internal database user name and host information
go
github.com/zitadel/zitadel
High
over 1 year ago
ZITADEL's Improper Lockout Mechanism Leads to MFA Bypass
go
github.com/zitadel/zitadel
High
over 1 year ago
ZITADEL's Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP Bypass
go
github.com/zitadel/zitadel
High
over 1 year ago
Account Takeover via Session Fixation in Zitadel [Bypassing MFA]
go
github.com/zitadel/zitadel
High
almost 2 years ago
ZITADEL Account Takeover via Malicious Host Header Injection
go
github.com/zitadel/zitadel
High
almost 2 years ago
ZITADEL race condition in lockout policy execution
go
github.com/zitadel/zitadel
Moderate
almost 2 years ago
ZITADEL's password reset does not respect the "Ignoring unknown usernames" setting
go
github.com/zitadel/zitadel
Moderate
over 2 years ago
Zitadel RefreshToken invalidation vulnerability
go
github.com/zitadel/zitadel