CVE-2026-29067 | Zitadel up to 4.7.0 Password Reset X-Forwarded-Host redirect (GHSA-pfrf-9r5f-73f5 / EUVD-2026-10143)
A vulnerability was found in Zitadel up to 4.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Password Reset Handler. The manipulation of the argument X-Forwarded-Host results in open redirect.
This vulnerability was named CVE-2026-29067. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.