| id: GO-2026-5197 |
| modules: |
| - module: github.com/zitadel/zitadel |
| versions: |
| - fixed: 1.80.0-v2.20.0.20260615092437-6082e59d47c1 |
| vulnerable_at: 1.80.0-v2.20 |
| summary: 'ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers in github.com/zitadel/zitadel' |
| cves: |
| - CVE-2026-55670 |
| ghsas: |
| - GHSA-6x8v-2fq5-2229 |
| references: |
| - advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-6x8v-2fq5-2229 |
| - fix: https://github.com/zitadel/zitadel/commit/6082e59d47c17a9d54a6b0556b3f31559d7c620a |
| - web: https://github.com/zitadel/zitadel/releases/tag/v4.15.2 |
| source: |
| id: GHSA-6x8v-2fq5-2229 |
| created: 2026-06-25T01:56:58.075003348-04:00 |
| review_status: UNREVIEWED |