blob: 03452836c09188920aaaaefa3d9962c6f8907db4 [file]
id: GO-2026-5197
modules:
- module: github.com/zitadel/zitadel
versions:
- fixed: 1.80.0-v2.20.0.20260615092437-6082e59d47c1
vulnerable_at: 1.80.0-v2.20
summary: 'ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers in github.com/zitadel/zitadel'
cves:
- CVE-2026-55670
ghsas:
- GHSA-6x8v-2fq5-2229
references:
- advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-6x8v-2fq5-2229
- fix: https://github.com/zitadel/zitadel/commit/6082e59d47c17a9d54a6b0556b3f31559d7c620a
- web: https://github.com/zitadel/zitadel/releases/tag/v4.15.2
source:
id: GHSA-6x8v-2fq5-2229
created: 2026-06-25T01:56:58.075003348-04:00
review_status: UNREVIEWED