CVE-2025-67717: medium-severity vulnerability in zitadel
Zitadel Discloses the Total Number of Instance Users
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 disclose the total number of instance users to authenticated users, regardless of their specific permissions. While this does not leak individual user data or PII, disclosing the total user count via the totalResult field constitutes an information disclosure vulnerability that may be sensitive in certain contexts. This issue is fixed in versions 3.4.5 and 4.7.2.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
zitadel · zitadelRelated CVEs — zitadel
In the same product, most dangerous first.
CVE-2024-49757HIGHZitadel User Registration Bypass VulnerabilityEPSS 2.5%CVE-2022-36051HIGHBroken Authorization in ZITADEL ActionsEPSS 1.0%CVE-2024-28855HIGHZITADEL vulnerable to improper HTML sanitizationEPSS 0.8%CVE-2024-29892MEDIUMZITADEL's actions can overload reserved claimsEPSS 0.8%CVE-2023-49097HIGHZITADEL vulnerable account takeover via malicious host header injectionEPSS 0.8%CVE-2024-29891HIGHZITADEL Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP BypassEPSS 0.8%