Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY71 SECURITY RECORDS

zitadel

zitadel

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at Zitadel, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-105215 4 Oct 2026 zitadel: < 4.16.2, < 3.4.14 zitadel: 4.16.2, 3.4.14 Update reference ↗
CVE-2026-105214 4 Oct 2026 zitadel: < 4.16.2 zitadel: 4.16.2 Update reference ↗
CVE-2026-105213 4 Oct 2026 zitadel: < 4.17.1 zitadel: 4.17.1 Update reference ↗
CVE-2026-105212 4 Oct 2026 zitadel: < 4.16.2, < 3.4.14 zitadel: 4.16.2, 3.4.14 Update reference ↗
CVE-2026-105211 4 Oct 2026 zitadel: < 4.17.1 zitadel: 4.17.1 Update reference ↗
CVE-2026-105210 4 Oct 2026 zitadel: < 4.17.1, < 3.4.15 zitadel: 4.17.1, 3.4.15 Update reference ↗
CVE-2026-105209 4 Oct 2026 zitadel: < 4.17.1, < 3.4.15 zitadel: 4.17.1, 3.4.15 Update reference ↗
CVE-2026-105208 4 Oct 2026 zitadel: < 4.17.3, ≤ 4.19.4 zitadel: 4.17.3 Update reference ↗
CVE-2026-105207 4 Oct 2026 zitadel: < 4.17.3, ≤ 4.19.4 zitadel: 4.17.3 Update reference ↗
CVE-2026-105206 4 Oct 2026 zitadel: < 4.17.3, ≤ 4.19.4 zitadel: 4.17.3 Update reference ↗
CVE-2026-85056 24 Sep 2026 zitadel: >= 4.0.0, < 4.16.1 4.16.1. Update reference ↗
CVE-2026-85057 24 Sep 2026 zitadel: >= 3.0.0, < 3.4.13, >= 4.0.0, < 4.16.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-76081 14 Sep 2026 zitadel: < 4.16.0 4.16.0. Update reference ↗
CVE-2026-54693 29 Jul 2026 >= 2.43.0, <= 2.71.19; >= 3.0.0-rc.1, < 3.4.11; >= 4.0.0-rc.1, < 4.15.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56668 10 Jul 2026 < 4.15.3 4.15.3. Update reference ↗
CVE-2026-56666 10 Jul 2026 < 4.15.3 4.15.3. Update reference ↗
CVE-2026-56667 10 Jul 2026 < 4.15.3 4.15.3. Update reference ↗
CVE-2026-56665 10 Jul 2026 >= 4.0.0-rc.1, < 4.15.2; < 3.4.12 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56664 10 Jul 2026 >= 4.0.0-rc.1, < 4.15.2; < 3.4.12 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-55672 10 Jul 2026 >= 4.0.0-rc.1, < 4.15.2; < 3.4.12 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-55671 10 Jul 2026 < 4.15.2 4.15.2. Update reference ↗
CVE-2026-55670 10 Jul 2026 < 4.15.2 4.15.2. Update reference ↗
CVE-2026-55669 10 Jul 2026 >= 4.0.0-rc.1, < 4.15.2; < 3.4.12 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-44671 14 May 2026 >= 2.71.11, < 3.4.10; >= 4.0.0, < 4.15.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-33132 20 Mar 2026 >= 4.0.0-rc.1, < 4.12.3; >= 3.0.0-rc.1, < 3.4.9; < 1.80.0-v2.20.0.20260317120401-d90285929ca0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-32132 11 Mar 2026 >= 4.0.0, < 4.12.2; < 3.4.8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-32131 11 Mar 2026 >= 4.0.0, < 4.12.2; < 3.4.8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-32130 11 Mar 2026 >= 4.0.0, < 4.12.2; >= 2.68.0, < 3.4.8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-29067 7 Mar 2026 >= 4.0.0-rc.1, < 4.7.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-29193 7 Mar 2026 >= 4.0.0, < 4.12.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-29192 7 Mar 2026 >= 4.0.0, < 4.12.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-29191 7 Mar 2026 >= 4.0.0, < 4.12.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-27946 26 Feb 2026 >= 4.0.0, < 4.11.0; < 3.4.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-27945 26 Feb 2026 >= 2.59.0, < 4.11.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-27840 26 Feb 2026 >= 4.0.0, < 4.11.0; >= 3.0.0, < 3.4.7; >= 2.31.0, <= 2.71.19 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-23511 15 Jan 2026 >= 4.0.0, < 4.9.1; < 3.4.6 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-67717 11 Dec 2025 < 1.80.0-v2.20.0.20251210; >= 2.44.0, < 3.4.5; >= 4.0.0-rc.1, < 4.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-67495 9 Dec 2025 < 1.80.0-v2.20.0.20251208091519-4c879b47334e; >= 1.83.4, <= 1.87.5; >= 4.0.0-rc.1, < 4.7.1 4.7.1. Update reference ↗
CVE-2025-67494 9 Dec 2025 < 1.80.0-v2.20.0.20251208091519-4c879b47334e; >= 1.83.4, <= 1.87.5; >= 4.0.0-rc.1, < 4.7.1 4.7.1. Update reference ↗
CVE-2025-64717 13 Nov 2025 >= 4.0.0-rc.1, < 4.6.6; >= 3.0.0-rc.1, < 3.4.4; >= 2.50.0, < 2.71.19 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-64431 7 Nov 2025 >= 4.0.0-rc.1, < 4.6.3; >= 1.80.0-v2.20.0.20250414095945-f365cee73242, < 1.80.0-v2.20.0.20251105083648-8dcfff97ed52 4.6.3. Update reference ↗
CVE-2025-64103 29 Oct 2025 >= 4.0.0-rc.1, < 4.6.0; >= 3.0.0-rc.1, < 3.4.3; >= 2.55.0, < 2.71.18; >= 2.54.3, <= 2.54.10; >= 2.53.6, <= 2.53.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-64102 29 Oct 2025 >= 4.0.0-rc.1, < 4.6.0; >= 3.0.0-rc.1, < 3.4.3; >= 2.0.0, < 2.71.18 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-64101 29 Oct 2025 >= 4.0.0-rc.1, < 4.6.0; >= 3.0.0-rc.1, < 3.4.3; >= 2.0.0, < 2.71.18 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-57770 22 Aug 2025 < 2.71.15; >= 3.0.0, < 3.4.0; >= 4.0.0, < 4.0.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-53895 15 Jul 2025 = 4.0.0-rc.1; >= 3.0.0, < 3.3.1; >= 2.53.0, < 2.70.14; >= 2.71.0, < 2.71.13 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-48936 30 May 2025 < 2.70.12; >= 2.71.0, <= 2.71.10; >= 3.0.0-rc1, < 3.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-46815 6 May 2025 >= 3.0.0-rc.1, < 3.0.0; < 2.70.10; >= 2.71.0, < 2.71.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-31124 31 Mar 2025 >= 2.62.0, < 2.63.9; >= 2.64.0-rc.1, < 2.64.6; >= 2.65.0-rc.1, < 2.65.7; >= 2.66.0-rc.1, < 2.66.16; >= 2.67.0-rc.1, < 2.67.13; >= 2.68.0-rc.1, < 2.68.9; >= 2.69.0-rc.1, < 2.69.9; >= 2.70.0-rc.1, < 2.70.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-31123 31 Mar 2025 >= 2.62.0, < 2.63.9; >= 2.64.0-rc.1, < 2.64.6; >= 2.65.0-rc.1, < 2.65.7; >= 2.66.0-rc.1, < 2.66.16; >= 2.67.0-rc.1, < 2.67.13; >= 2.68.0-rc.1, < 2.68.9; >= 2.69.0-rc.1, < 2.69.9; >= 2.70.0-rc.1, < 2.70.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.